You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Tracker for AUDIT.md > 6. Validate Settings, Rulesets, and Secrets. Filed under #1315's roll-up of the open prose backlog: every finding a bundle issue enumerated against this unit is listed here once, one line each, naming the issue it came from, and the bundle is closed as a duplicate of this tracker so the finding is not lost and the bundle stops being a unit of work. A new pre-existing finding on this unit gathers here per pr-review-conduct's Merge Gate, numbering continuing this list. This tracker closes when the unit is rewritten and each line below is settled or superseded.
"It preserves and reports bypass_actors without asserting them" describes apply-mode behavior. In check the live list is only read and printed, and nothing is preserved. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
The check command is given with no prerequisites, where it hard-fails without admin on the target, an authenticated gh, jq, and a Python interpreter for the description resolution. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
"read its Secrets section" names a section audit.py does not print. Secrets findings are secrets:-prefixed lines in one flat block, and a clean repo prints no secrets line at all. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
"confirming each required name exists" describes only the presence half: audit.py also raises a defect for a forbidden name present and a drift for a stale name claimed by no mechanism. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
"where the mechanism needs it (Docker Hub, codegen App), the Dependabot store too" is incomplete against spec/secrets.json, where nuget-oidc and codecov also declare both stores. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
The snippet's package-ecosystem regex accepts a bare or double-quoted value only, so a single-quoted YAML value reports MISSING, a false drift on the check the bullet mechanizes. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
The snippet's four "|| exit 1" tails terminate an interactive shell when pasted, and under set -e a repo without .devcontainer or with an empty dependabot.yml exits non-zero while every printed line says present. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
"a repo whose dependabot-updates or update-graph runs are all cancelled with zero steps has this problem" is asserted as diagnostic, and three sentences later called the only visible signal rather than a cause. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
"Detection stops there ... Remediation is a separate, manual action" is contradicted by the three imperative remediation sentences that follow it in the same bullet. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
"(the file exists, so its absence would instead be a file-presence letter)" binds its pronoun to the tree-implied ecosystem, inverting the classification the sentence just made. The intended subject is dependabot.yml. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
The lead-in "General settings, labels, and rulesets" names three of the six groups its body says the command checks, dropping the Dependabot security features, so no bullet advertises where those two are validated. (introduced by Declare the Fleet Label Set and Apply It Through configure.sh #1334, left open after its granted round)
"the derived settings and the registry description" over-claims: check asserts the description only when the registry declares one, and otherwise notes "Verify manually" while still reporting a match, where the bullet carves out only bypass_actors as reported rather than asserted. (introduced by Declare the Fleet Label Set and Apply It Through configure.sh #1334, left open after its granted round)
Tracker for
AUDIT.md > 6. Validate Settings, Rulesets, and Secrets. Filed under #1315's roll-up of the open prose backlog: every finding a bundle issue enumerated against this unit is listed here once, one line each, naming the issue it came from, and the bundle is closed as a duplicate of this tracker so the finding is not lost and the bundle stops being a unit of work. A newpre-existingfinding on this unit gathers here perpr-review-conduct's Merge Gate, numbering continuing this list. This tracker closes when the unit is rewritten and each line below is settled or superseded.