Skip to content

Review repo-sentinel baseline before enabling a remote gate #5

Description

@stacknil

Context

repo-sentinel-lite was previously available only as a local pre-push/manual hook in this repository. The original baseline numbers below are retained as historical context only; they are not canonical consumer evidence.

Historical context

  • Released repo-sentinel-lite v0.7.1: 146 unsuppressed error-level findings against the then-current main.
  • Historical upstream baseline snapshot: 275 active, 27 stale, 153 unmatched, and 4 ambiguous entries.
  • Upstream duplicate-fingerprint work was completed before the v0.8 adoption.

Resolution evidence

PR #8 merged the reviewed consumer integration:

  • Consumer repository SHA: 8d72ecd706aeaffa2893917ed93c99071454781d
  • Consumer PR: ci: adopt repo-sentinel-lite v0.8.1 consumer gate #8
  • Scanner: repo-sentinel-lite==0.8.1 from production PyPI
  • Scanner release commit: eed8f484ba3e50cf0e86b61591a52b744dadf56a
  • Exact audit command: python -m repo_sentinel baseline audit --format json --baseline .reposentinel-baseline.json .
  • Redacted audit artifact SHA-256: c2193422cdf638f173c33890eef455d88aed7b039e3f7dcc3bf43501902ab962
  • Current audit summary: active 272, relocated 7, changed 0, ambiguous 26, stale 0, unmatched 150
  • Active repo.required_file_missing: 0
  • Synthetic contract: PASS fixture, FAIL fixture, and redaction assertion passed in the independent clean clone
  • Remote workflow run: https://github.com/stacknil/sec-writeups-public/actions/runs/31955666162
  • Changed-file error gate: blocking and passed
  • Baseline audit: continue-on-error: true, passed without becoming a blocking policy
  • Workflow permissions: contents: read
  • No raw token values were included in repository, issue, or reviewer-facing output.

Decision

The acceptance criteria are complete. Consumer proof is pinned to stable v0.8.1, not the provider development branch. New error-level findings in changed files block pull requests; baseline drift remains a separate review signal.

Rollback

Remove .github/workflows/repo-sentinel-gate.yml to disable the remote gate while retaining the local pre-push hook. The local hook can be returned to its previous release pin if required.

Non-goals

  • No bulk baseline refresh for metric reduction.
  • No claim that repo-sentinel replaces human authorization, PII review, or the canonical placeholder validator.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions