Re-land the README gates from PRs 107 and 114 - #222
Merged
Merged
Conversation
Both PRs show as merged, but each was merged into a branch that had already been merged, so neither reached main (de4e8b6 and 79c6e1b, preserved on claude/readme-current). Re-applied by hand against today's README and package.json rather than cherry-picked. From 107: npm run test:readme fails when package.json has a test: script the README does not mention. On main the "Run it locally" block named eleven of thirty-eight. It now names all thirty-nine, grouped as core suites, focused suites, release and documentation gates, and the three that need a build. The check is one-directional on purpose, and now matches on a word boundary, so test:secret-erase is not satisfied by the line for test:secret-erase-core. Runs early in the ci job. From 114: the Security model section says what outside review covered. SECURITY-AUDIT.md's scope line is unchanged (the KEYM v1 container, the core, the encryptor UI, the dice tool, the CSP pipeline, CI), so the format the app writes today, now including v4's padded payload and the audio carrier, is stated as not in that scope. The documentation table row no longer calls it the current v2 audit. The gate binds the two files in both directions, and its subjects gain "KEYM v4". "KEYM v2" stays out of the list because the audit names it only under Remaining work. Negative controls, each confirmed applied before its result was read: - test:shamir line removed from README: fails, names test:shamir. - test:secret-erase line removed, test:secret-erase-core kept: fails, names test:secret-erase. The old includes() check passes this case. - the disclaimer paragraph removed: fails, says silence reads as audited. - an addendum naming passkey slots and KEYM v4 appended to SECURITY-AUDIT.md: fails, names both subjects.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PR #107 and PR #114 show as merged, but each was merged into a branch that had itself already been merged, so neither reached
main. This is the same failure CLAUDE.md records for PR #23. Their commits (de4e8b6,79c6e1b) are preserved onclaude/readme-current. Confirmed on a full (unshallowed) clone that neither is an ancestor ofmainand thatgit cherryshows both as absent.Re-applied by hand against today's README and
package.json, not cherry-picked.Changes
npm run test:readme(scripts/readme-scripts-test.mjs, from Document every test script, and fail when one goes undocumented #107). Fails whenpackage.jsonhas atest:script the README does not mention. It now matches on a word boundary, sotest:secret-eraseis not satisfied by the line fortest:secret-erase-core. Runs early in thecijob, after typecheck.main. It now lists all 39 (includingtest:readme), grouped as core suites, focused suites, release and documentation gates, and the three that need a build (verify-recipe,palette,icons, matching where CI runs them afternpm run build). Each one-line description is taken from that script's own header.SECURITY-AUDIT.md's scope line is unchanged (the KEYM v1 container,keymaker-crypto.ts, the encryptor UI, the dice tool, the CSP pipeline, CI). The paragraph names the current format as not in that scope, updated to include KEYM v4's padded payload and the audio carrier. It says external review passes exist for parts of it, and that nothing in the repo records one for v4. The Documentation table row no longer calls it the "current Keymaker v2 audit".SECURITY-AUDIT.mdin both directions. Subjects areKEYM v3,KEYM v4,slot_table_mac,Shamir,passkey.KEYM v2is left out on purpose because the audit names it only under "Remaining work".Test plan
npm run test:readmepasses: 39 of 39 documented, audit scope matches.test:shamirline removed from README → fails, namestest:shamir.test:secret-eraseline removed,test:secret-erase-corekept → fails, namestest:secret-erase. The oldincludes()check wrongly passes this case.SECURITY-AUDIT.md→ fails, names both.npm run typecheck,test:release-gate,test:release-recipe,test:release-notes,test:reproduced-manifestpass;ci.ymlparses.Generated by Claude Code