Skip to content

Security: add fail-closed public privacy gate - #1

Merged
fscfede-beep merged 1 commit into
mainfrom
security/privacy-drift-gate
Sep 1, 2026
Merged

fscfede-beep merged 1 commit into
mainfrom
security/privacy-drift-gate

Conversation

@fscfede-beep

Copy link
Copy Markdown
Owner

Adds a deny-hash privacy gate for all public changes and validates commit author/committer metadata against the approved GitHub noreply identity. Actions are pinned, checkout credentials are not persisted, and missing/malformed deny material fails closed. Existing binding-attestation semantics are unchanged.

@fscfede-beep
fscfede-beep merged commit 8b0dd41 into main Sep 1, 2026
1 check passed
@fscfede-beep
fscfede-beep deleted the security/privacy-drift-gate branch September 1, 2026 04:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant