Skip to content

security: standardize secret scanning on TruffleHog - #47

Merged
hyperpolymath merged 13 commits into
mainfrom
campaign-253/migrate-deno
Jun 11, 2026
Merged

security: standardize secret scanning on TruffleHog#47
hyperpolymath merged 13 commits into
mainfrom
campaign-253/migrate-deno

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Standardizing on TruffleHog.

hyperpolymath and others added 10 commits May 30, 2026 21:27
…ds#253)

Class A (pure-Deno port). Deletes redundant package.json — deno.json
already covers all tooling (rescript build/watch/clean via npm: specifier,
test/lint/fmt/check via deno) and imports map covers all deps.

Refs: standards#253 STEP 3 (smallest-first batch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- C001: CodeQL language fixes
- C002: License identifier standardization
- C003: Outdated actions audit
- C004: Pin standards refs to SHA 861b5e9
- C005: Add workflow-level permissions
@hyperpolymath
hyperpolymath enabled auto-merge June 11, 2026 21:33
@hyperpolymath
hyperpolymath merged commit e1a7a6f into main Jun 11, 2026
10 of 12 checks passed
@hyperpolymath
hyperpolymath deleted the campaign-253/migrate-deno branch June 11, 2026 23:33
hyperpolymath added a commit that referenced this pull request Jul 17, 2026
…crawl on warm-cache miss (#70)

Closes the loop on the e2e redness: `main`'s e2e run #47 failed on both
attempts (I re-ran its failed jobs to confirm determinism). Local
reproduction on the exact toolchain identified two causes — one
introduced by #68, one long-latent:

## 1. `:live_download` leaked into the default suite (regression from
#68)

`test_helper.exs` never excluded `:live_download` — those tests were
only kept out of `mix test` by riding on their `:external_api` tag. When
#68 removed that tag (correctly, to fix the `--include`/`--exclude`
interaction), the ~10–50MB download tests fell into the **default**
suite, where the e2e-opsm "Run all tests" step runs them on runners
without nickel → `{:error, {:nickel_not_installed, "zig"}}` × 2. Fix:
exclude `:live_download` explicitly in `ExUnit.start/1`; run them
deliberately via `--include live_download`.

## 2. `HyperpPolymathForge.fetch_package/2` re-crawled the GitHub org on
every miss

A per-name cache miss triggered `refresh_index()` — a full
unauthenticated org listing — even when the index was already populated.
Any absent package name burned rate limit, and on CI runners the 403
surfaced as `{:error, {:http_error, 403}}` instead of `{:error,
:not_found}`. The ETS-seeded test at `hyperpolymath_forge_test.exs:321`
documents the intended contract ("cache is non-empty, so refresh_index
won't fire") — the implementation just never honored it. A miss against
a warm cache now returns `:not_found` with no network I/O; a cold cache
still refreshes and still propagates refresh errors. The warmth
criterion mirrors the existing `ensure_index/0`.

## Verified (OTP 28.3.1 / Elixir 1.19.5)

- `mix compile --warnings-as-errors` — clean
- Full default suite (`mix test`) — **807 tests, 0 failures**
(previously 2)
- e2e step (`--include e2e --include integration`) — 55/55
- runtime-api step (`--include external_api --exclude live_download`) —
9/9, 6 excluded
- `just toolchain-check` — green

With this, all three e2e workflow test commands pass locally against
`main`'s toolchain; the only expected remaining red on this PR is the
pre-existing governance ReScript policy check (fails identically on
`main`; owner-decision).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Kq24sZCEohSrNFXSuEuz6C

---
_Generated by [Claude
Code](https://claude.ai/code/session_01Kq24sZCEohSrNFXSuEuz6C)_

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants