Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Guard direct scanner filesystem reads and symlink targets when protected-directory scanning is disabled. Preserve existing subprocess behavior. The browser-only fix is already in the baseline.
Targeted regression fixes
Inventory contract
Protected-location omissions are expected inventory behavior. This PR adds no backend retention contract or new wire fields. Proposed API companions step-security/agent-api#10980 and step-security/agent-api#10981 were closed without merge or deployment. Existing failed-scan handling is preserved. Python's partial marker remains internal; global collection runs every scan, while delta state tracks successful uploaded bodies.
Current verification
Final signed head: b2a02fd, following dc1fcfc.
Integration evidence
Final b2a02fd macOS26/Linux/Windows run passed: https://github.com/step-security/integration-test/actions/runs/36868474724. Main suites passed 66/63/62 respectively, zero failed; lifecycle and data-size checks also passed.
Final b2a02fd macOS27-only run passed: https://github.com/step-security/integration-test/actions/runs/36874311803. Main suite: 62 passed, zero failed; lifecycle, applicable threat-intel and data-size checks also passed. Linux and Windows were intentionally skipped. It was dispatched sequentially to avoid workflow concurrency cancellation. All 12 product CI checks passed on the same final head. Both new commits have GitHub-verified signatures; the branch is clean and pushed.
The dc1fcfc campaign passed macOS26/Linux/Windows: https://github.com/step-security/integration-test/actions/runs/36864642270. It predates the additional Node cache correction and does not certify the final head.
Earlier a599377 runs passed without weakened assertions:
Those earlier runs do not validate the current head. PR remains draft and unmerged. No zero-regression guarantee is claimed.
Full scenario ledger: 2026-09-24-dmg-pr227-validation-runbook.md in the shared workspace docs directory.