Skip to content

Run selected audit plugins independently in a sandbox - #699

Merged
AdamFrisby merged 2 commits into
mainfrom
codeybox/446c85dc
Oct 5, 2026
Merged

AdamFrisby merged 2 commits into
mainfrom
codeybox/446c85dc

Conversation

@AdamFrisby

Copy link
Copy Markdown
Owner

Automated via CodeyBox — work item 446c85dca19642b19b1e88aa3ecb319b

Initiated by CodeyBox operator


Co-Authored-By: CodeyBox noreply@codeybox.invalid
🤖 Generated with CodeyBox

AdamFrisby and others added 2 commits October 5, 2026 07:07
… disabled by default)

Implements the approved standalone AuditRun contract: durable run identity
with Queued->Provisioning->Running->Collecting->terminal lifecycle, explicit
auditor-or-profile selection, SHA resolution frozen in provenance, credential-
free tool execution through registered auditors, bounded redacted logs with
separate digested artifacts, idempotent create with read-back replay and 409
on body clash, cancellation with partial-findings preservation, restart
reconciliation that never auto-reruns tools, and project-scoped REST/CLI
surfaces. No PipelineRunner audit-loop reuse, no agent coupling, no
commit/merge/push paths.

Evidence: committed grep fixture proves Findings then Pass at distinct SHAs
via a real shell auditor and real process execution; 45 service/store/API
tests and 5 CLI tests; adjacent audit regression slice (208 tests) green.

    CodeyBox-Prompt-Revision: 1
    Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
CodeyBox-WorkItem: 446c85dca19642b19b1e88aa3ecb319b
CodeyBox-Agent: copilot/muse-spark-1.3-contributor
CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
@AdamFrisby
AdamFrisby merged commit 54eb834 into main Oct 5, 2026
@AdamFrisby
AdamFrisby deleted the codeybox/446c85dc branch October 5, 2026 08:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant