Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A coverage unit could pass validation even when its local-check artifact did not exist. The coverage CLI now verifies retained files for both live checks and archived attempts, so missing evidence cannot support a successful coverage validation.
Fixes #21.
Changes
--output-dirfor exported ledgers.validateDocument(ledger, { outputDir })enables filesystem checks.Validation
node --test skills/security-audit/validate-findings.test.cjs skills/security-audit/validate-coverage-ledger.test.cjsgit diff --checkpassed.AI Assistance Disclosure
AI tools were used to assist with implementation review, test development, documentation, and reasoning about edge cases. All submitted changes, security assumptions, test results, and validation claims were reviewed and verified by the contributor. AI-generated output was not treated as independent evidence of correctness or as a substitute for the validation described above.
The artifact check assumes a trusted, stable, parent-owned output tree. It verifies file presence/type, not evidence contents, and does not replace race-safe artifact promotion or independent finding verification. Native Windows CLI file opening continues to fail closed when the required OS protections are unavailable.