Security review: Repo tooling setup
Security review (gate)
Mechanism: the built-in
/security-reviewskill (Claude Code) plus the-loop's checklist (reference/security.md), both againstgit diff origin/main...HEAD.Outcome: pass. No finding blocks.
Findings:
# Finding Severity Disposition 1 docs.ymlgrantspages: writeandid-token: writeat workflow level, so thebuildjob (which runsbun install) holds them too, not onlydeploy. Runs only on pushes tomain, never on PR codelow (hardening) Accepted for now; moving the two scopes onto deployis a one-line follow-up, offered in the reviewer briefingChecklist:
Check Result Untrusted PR code gets no write token or OIDC (abuse case 1) ci.ymlusespull_request, neverpull_request_target; workflow-levelcontents: read; no job widens it. Tested bytests/unit/test_workflows.pyOnly release.yml/ envpypican publish (abuse case 2)id-token: writeonly onpublish, which setsenvironment: pypi; PyPI's trusted publisher names this workflow and environment. TestedFailed checks block bump and publish (abuse case 3) publishneedsbumpneedschecks(ci.yml). TestedNo credentials in the repository or evidence (abuse case 4) No secrets.*beyond the implicitGITHUB_TOKEN; evidence redacted (scratch and home paths, placeholder git identity)Script injection No attacker-controlled github.eventfield reaches arun:step.head_commit.messageis used only in anif:expression (and only on pushes tomain); the version reaches the shell throughenv:Unsafe deserialization Tests use yaml.safe_loadSupply chain Python tools pinned by uv.lock, docs deps bybun.lock(--frozen-lockfile), markdownlint by exact version; actions on major tags (SHA pinning not adopted — hardening)Human sign-off: required — risk tier 4 (
.github/workflows/**, publish rights). Requested from @MadaraUchiha-314 in the reviewer briefing on PR #5; pending.
Built-in review
/security-review: no findings at confidence 8 or higher. It checked the trigger and permission model of all three workflows (no pull_request_target, no event data in run: steps, the version passed through env:, bump holds no OIDC token, publish runs no repository code and only downloads the same run's artifact), the pre-commit hooks, the VitePress config (sidebar text built from repository file names, escaped by VitePress), YAML loading (safe_load only) and the evidence files (no tokens, emails, home or /tmp paths, hostnames). It noted tag-pinned actions (rather than SHA-pinned) as hardening, out of scope.