Skip to content

fix: clear security advisories and preserve failure diagnostics - #20

Open
jaden3824 wants to merge 1 commit into
mainfrom
codex/urusilla-security-review-20261001
Open

jaden3824 wants to merge 1 commit into
mainfrom
codex/urusilla-security-review-20261001

Conversation

@jaden3824

@jaden3824 jaden3824 commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Website dependency checks were blocked by multiple security advisories, discarded session replies lost their reported token usage, and cached GitHub activity could be shown as a fresh live result. This change clears the current dependency audit and preserves those failure diagnostics.

  • Patch Next and the necessary Cloudflare dependency chain, refresh the affected transitive lock entries, and pin Miniflare's Undici to its security patch. The resulting clean install reports zero vulnerabilities.
  • Record a returned session reply's provider usage before context, binding, and token-ceiling checks can discard it. Preserve the existing terminal rejection and unknown-cost behavior when no valid reply was returned.
  • Show the existing unavailable/snapshot state for status: stale activity responses and guard Cloudflare's cache surface for TypeScript and ordinary environments.
  • Incorporate the hardened AgentMeasure workflow proposed by roy-tong in ci: run AgentMeasure conformance on the two urusilla vectors #15. Its original full-pin run failed during action extraction because the pinned repository contains an unrelated dangling dependency symlink. Check out only the same commit's action and validator files, retaining read-only permissions, disabled credential persistence, and all five required invariants. Generic AgentMeasure checks continue to complement the existing Urusilla-specific fixture checks.
  • Correct the outdated content-bound compiler description and regenerate the bounded decoder QA snapshot and input digests after the README change.

Validation: clean website install and audit (zero vulnerabilities), lint, production build, and TypeScript check passed. All 248 hybrid-runtime tests and 63 contribution ledger/checkpoint/adjudication tests passed. The remaining offline integration batch ran 309 tests with 298 passes, 11 unavailable optional-data/dependency skips, and no failures. Both AgentMeasure fixtures passed their five supported invariants in a credential-free local run at the exact pinned commit. Decoder QA passed 5,232 behavior checks, 101 baseline tests, and 15 QA tests with zero known findings; adoption and decoder artifact digests were verified. The root suite ran 352 tests with no failures and 11 optional-asset skips; all 444 initial-goal tests passed. At final commit 48b62b2, all eight Conformance jobs passed on GitHub, including Python 3.11, Python 3.13, tokenizer accounting, website, cross-runtime, offline integration, strong-codec, and package build (run 36833529473, attempt 2). The separate AgentMeasure conformance job also passed (run 36833534313). The earlier transient dependency-download failure is superseded by this successful execution; canceled duplicate-run records remain visible in the PR check history.

Prepared with Codex agent assistance. These are same-project implementation and regression checks. They add no provider-backed research result, independent reproduction, adoption, or general token-saving evidence. The protocol and frozen language version remain unchanged. The website has not been deployed by this PR.

Refs #15, #16, #17, #18, #19.

@jaden3824
jaden3824 force-pushed the codex/urusilla-security-review-20261001 branch from d872e78 to 48b62b2 Compare October 1, 2026 07:58
@jaden3824
jaden3824 marked this pull request as ready for review October 1, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant