7 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-09-03T12:03:48Z.
Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.
0877f84 — Share the token bucket, and stop dev servers binding the tailnet
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-03 22:55:31 -0700
- Refs: remotes/origin/server-password-harden
- Files:
.github/audit/application-security.md
- View diff
0c54eee — Make public Funnel exposure an audited posture
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-03 20:55:48 -0700
- Refs: remotes/origin/server-password-harden
- Files:
.github/audit/application-security.md
- View diff
1f2bde1 — Split security-application into security-local and security-remote; page per audience
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-03 13:58:38 -0700
- Refs: main,remotes/origin/browser-icons remotes/origin/fix/ui-geometry-docs-and-tests,remotes/origin/main remotes/origin/server-password-harden
- Files:
.github/audit/application-security.md
.github/workflows/security-audit.yaml
- View diff
5237e34 — Stop test servers binding the tailnet, and tighten the Funnel rule
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-03 23:09:17 -0700
- Refs: remotes/origin/server-password-harden
- Files:
.github/audit/application-security.md
- View diff
693adee — Allow nested iframe proxy documents
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-03 17:12:20 -0700
- Refs: main,remotes/origin/browser-icons remotes/origin/fix/ui-geometry-docs-and-tests,remotes/origin/main remotes/origin/server-password-harden
- Files:
.github/audit/application-security.md
- View diff
87981f5 — Relay nested iframe shim messages
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-03 17:24:36 -0700
- Refs: main,remotes/origin/browser-icons remotes/origin/fix/ui-geometry-docs-and-tests,remotes/origin/main remotes/origin/server-password-harden
- Files:
.github/audit/application-security.md
- View diff
adb8ae7 — Keep nested frame locations local
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-03 17:37:15 -0700
- Refs: main,remotes/origin/browser-icons remotes/origin/fix/ui-geometry-docs-and-tests,remotes/origin/main remotes/origin/server-password-harden
- Files:
.github/audit/application-security.md
- View diff
7 unexplained commit(s) in the audit window (
.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since2026-09-03T12:03:48Z.Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.
0877f84— Share the token bucket, and stop dev servers binding the tailnet.github/audit/application-security.md0c54eee— Make public Funnel exposure an audited posture.github/audit/application-security.md1f2bde1— Split security-application into security-local and security-remote; page per audience.github/audit/application-security.md.github/workflows/security-audit.yaml5237e34— Stop test servers binding the tailnet, and tighten the Funnel rule.github/audit/application-security.md693adee— Allow nested iframe proxy documents.github/audit/application-security.md87981f5— Relay nested iframe shim messages.github/audit/application-security.mdadb8ae7— Keep nested frame locations local.github/audit/application-security.md