Harden release validation and cache provenance - #18
Merged
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Verify and copy cached source bytes under the same lock before adapter or archive parsing, and redact OAuth authorization codes in provenance URLs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Allow verified snapshots to reuse recorded version and as_of metadata when callers do not constrain those fields, and cover Felten workbook and archive replacement paths. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Honor omitted cache provenance constraints
Parse the exact archive snapshot created during cache verification or commit, document shared-path mutability, and narrow credential redaction to explicit normalized OAuth and cloud parameter names. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This was referenced Jul 10, 2026
Recognize OAuth verifier and consumer credential aliases across normalized URL provenance surfaces without hiding benign parameter names. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use supported SHA-256 hashing, ownership-safe cache coordination, local source snapshots, and hardened URL redaction. Add R 4.1 CI coverage and deterministic concurrency tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the existing release check matrix unchanged and validate the built, installed package on R 4.1 without invoking the legacy Pandoc citeproc path. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Release lock directories nonrecursively, redact network-path authorities, and retain recoverable transaction state across injected registration and teardown failures. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use safe URL path filenames or raw URL SHA-256 identities, redact opaque credential-bearing URL components, and preserve content-aware workbook and tabular parsing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve supported-R hashing, cache lock ownership, local snapshot atomicity, URL redaction, transaction cleanup, and credential-safe cache naming.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
as_of, or digest constraints; compare credential-safe URL fingerprints and requireforce = TRUEreplacementValidation
devtools::document()devtools::test(): 726 passedR CMD check --as-cran: 0 errors, 0 warnings, 1 expected note for the development/new-submission versionRscript tools/validate-clean-install.R --rounds=2pkgdown::check_pkgdown()and fullpkgdown::build_site(preview = FALSE)Release-only notes
0.5.0.9000.