Skip to content

Harden HTML extraction and evidence file boundaries - #2

Merged
omar07ibrahim merged 5 commits into
mainfrom
codex/codeql-content-and-file-hardening
Aug 10, 2026
Merged

Harden HTML extraction and evidence file boundaries#2
omar07ibrahim merged 5 commits into
mainfrom
codex/codeql-content-and-file-hardening

Conversation

@omar07ibrahim

@omar07ibrahim omar07ibrahim commented Aug 10, 2026

Copy link
Copy Markdown
Owner

What changed

  • replaces regex-based script/style stripping with a standard-library HTML parser
  • keeps snapshot and evidence staging files owner-only throughout their private lifecycle
  • adds regression coverage for spaced closing tags, executable snapshots, and publication modes
  • adds a read-only deterministic refresh and adoption protocol for source-bound evidence

Verified evidence

  • hosted refresh run 31382249540 regenerated and checked both real bundles
  • all 13 non-manifest PNG, GIF, SVG, receipt, and CLI artifact identities remained byte-exact
  • only the two provenance manifests changed, binding 72 handoff sources and 12 DeepThink sources
  • final committed-bundle run 31382919187 verified both adopted bundles without checkout mutation

Verification

  • complete locked CPython 3.12 offline suite
  • Actions and Python CodeQL with zero PR alerts
  • independent handoff and DeepThink evidence replay

@omar07ibrahim
omar07ibrahim merged commit 135c62c into main Aug 10, 2026
6 checks passed
@omar07ibrahim
omar07ibrahim deleted the codex/codeql-content-and-file-hardening branch August 10, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant