Pulse/scripts
pulse-triage[bot] 603d4cad14 Keep security administration recipes credential-safe
Use private header and passphrase files for copied API requests, check protected access instead of public health, and preserve actual transfer and lockout permissions. Replace unsafe legacy credential setup and key cleanup, explain deployment-specific recovery, and align existing mobile security guidance with retirement.

Contract-Neutral: Existing security guidance, shipped mirrors and executable documentation fixtures only; authentication, encryption, scopes, entitlements and runtime behaviour are unchanged.
Change-source: pulse-maintainer
2026-10-01 10:32:50 +01:00
..
dev
eval
installtests Integrate reviewed credential-safe Proxmox bootstrap and demo sampler reuse 2026-10-01 09:06:11 +01:00
intelligence_lab Document RG-06 autonomy proof runner 2026-07-13 18:32:56 +01:00
lib backend and governance: MCP contract, agent capabilities, API, and release-control 2026-06-23 17:26:15 +01:00
lint-fixer
release_control Bind qualification to the complete current filesystem source 2026-10-01 07:33:49 +01:00
tests Keep security administration recipes credential-safe 2026-10-01 10:32:50 +01:00
.go-version Advance release builds to Go 1.26.8 2026-09-04 07:20:28 +01:00
audit-private-boundary.sh Ratchet private boundary audit debt 2026-07-29 20:09:23 +01:00
backfill-release-assets.sh Add historical release asset backfill workflow 2026-04-22 17:25:58 +01:00
BENCHMARK_EVIDENCE.md fix(ci): bind benchmark samples to executed binary hashes 2026-09-06 13:32:05 +01:00
build-release-binaries.sh Advance release builds to Go 1.26.8 2026-09-04 07:20:28 +01:00
build-release.sh Advance release builds to Go 1.26.8 2026-09-04 07:20:28 +01:00
build-secure-runtime-qualification.sh Advance release builds to Go 1.26.8 2026-09-04 07:20:28 +01:00
bundle.manifest
bundle.sh
capture-release-note-visuals.sh feat(release): add visual changelog comparisons 2026-08-28 11:29:44 +01:00
check-alert-card-footer.cjs fix(alerts): align the Started run with the alert-card footer (#2119) 2026-09-21 14:31:27 +01:00
check-alert-diagnosis-ordering.mjs fix(alerts): ignore superseded delivery diagnosis responses 2026-09-06 17:17:36 +01:00
check-alert-dispatch-copy.mjs fix(alerts): distinguish dispatch from notification receipt 2026-09-06 15:12:07 +01:00
check-assistant-identity.mjs test(assistant): add portable identity browser regression 2026-09-06 12:29:50 +01:00
check-backup-app-refresh.mjs test(web): qualify backup refresh through application boundaries 2026-09-05 01:55:54 +01:00
check-backup-browser-polling.mjs Preserve backup coverage row focus across polling snapshots 2026-09-05 01:33:47 +01:00
check-bench-regression.sh Pair benchmark evidence on one runner 2026-09-04 13:13:04 +01:00
check-browser-lifecycle-control.mjs test(web): retain failing browser suspension control diagnostic 2026-09-08 07:00:33 +01:00
check-browser-single-session-control.mjs test(web): cover production incident refresh after tab suspension 2026-09-08 08:42:45 +01:00
check-clone-identity-guidance.cjs Make cloned-host identity guidance safe and persistent 2026-09-30 02:29:54 +01:00
check-community-troubleshooting.cjs Run troubleshooting browser proof with frontend styling 2026-09-30 00:33:11 +01:00
check-delivery-health-ordering.mjs Merge current main and verify diagnostic workflows 2026-09-06 04:22:09 +01:00
check-delivery-log-ordering.mjs fix(web): retain current delivery evidence across overlapping reads 2026-09-06 10:19:46 +01:00
check-delivery-server-error-copy.mjs fix(web): identify notification destination server failures 2026-09-08 12:54:21 +01:00
check-docs-fragment-navigation.cjs Document maintenance API and repair documentation section links 2026-09-21 07:23:24 +01:00
check-drawer-tab-retention.cjs fix(web): keep the drawer tab across transient snapshot changes (#1723) 2026-09-23 00:55:58 +01:00
check-github-release-immutability.sh Gate release publication on immutable setting 2026-08-29 22:41:04 +01:00
check-incident-request-ownership.mjs fix(alerts): discard pending history reads after clearing 2026-09-10 06:44:37 +01:00
check-navigation-admission-race.mjs test(web): qualify superseded admission and diagnose narrow table access 2026-09-05 17:57:42 +01:00
check-overview-health-refresh.mjs Merge current main and verify diagnostic workflows 2026-09-06 04:22:09 +01:00
check-patrol-assistant-journey.mjs fix(ai): preserve uncertain investigation conclusions 2026-09-06 02:47:55 +01:00
check-pbs-host-history-correlation.cjs fix(web): retain PBS host target across transient snapshots (#1723) 2026-09-23 10:27:45 +01:00
check-recovery-feedback.mjs test(web): verify recovery preserves real settings-parent edits 2026-09-07 16:39:11 +01:00
check-thresholds-windowed-list.cjs fix(alerts): keep grouped-list window estimate off the header (#2130) 2026-09-20 23:50:19 +01:00
check-update-access-copy.mjs fix(web): avoid prescribing permissions from update access failures 2026-09-08 21:59:40 +01:00
check-webhook-test-save-parity.mjs fix(web): align webhook test custom fields with saved configuration 2026-09-08 23:29:31 +01:00
check-workflow-dispatch-inputs.py fix(release): restore release helper executable bits 2026-03-26 12:26:55 +00:00
check_docs_mirror.py Keep the docs guard out of the branch-tip link scan 2026-09-01 12:17:00 +01:00
check_public_docs.py Align TrueNAS guidance with JSON-RPC runtime 2026-09-01 18:32:39 +01:00
check_telemetry_schema_parity.py Harden Patrol activation telemetry 2026-08-28 11:35:41 +01:00
check_workflow_trust.py build(ci): refresh reviewed GitHub Actions pins 2026-09-20 08:16:44 +01:00
clean-mock-alerts.sh Route mock alert cleanup through managed runtime 2026-03-24 15:49:29 +00:00
cleanup.sh
cloud-backup.sh
com.pulse.hot-dev.plist.template
conformance-smoke.sh
demo_public_browser_smoke.cjs Use semantic demo connection status 2026-08-29 04:02:06 +01:00
dev-check.sh Switch script-reference integrity test from rg to git grep for portable CI 2026-05-12 00:30:43 +01:00
dev-deploy-agent.sh Harden dev agent deploy SSH host verification 2026-04-22 11:41:50 +01:00
dev-launchd-setup.sh fix(dev): preserve executable launchd wrapper mode 2026-08-27 17:54:10 +01:00
dev-launchd-wrapper.sh Supervise launchd dev runtime through hot-dev-bg 2026-03-24 15:39:55 +00:00
dev-prepush.sh fix(governance): align pre-push guard with CI 2026-08-27 17:07:58 +01:00
diagnose-root-pair.py fix(ci): archive durable root-pair candidate 2026-09-10 19:13:29 +01:00
diagnose-uuid-layout.py ci: add fixed UUID layout diagnostic without release gate waiver 2026-09-06 22:11:03 +01:00
docker-build.sh
ensure_test_assets.sh
exclusive-lock.mjs
generate-pulse-intelligence-docs.go backend and governance: MCP contract, agent capabilities, API, and release-control 2026-06-23 17:26:15 +01:00
generate-release-notes.sh Keep authored release notes compatible with safety checks 2026-10-01 05:28:54 +01:00
generate-self-hosted-feature-catalog.go Format generated self-hosted feature catalog with prettier in the generator 2026-07-27 11:58:05 +01:00
generate-types.go feat(assistant): mid-turn steering of the running response 2026-07-12 23:01:40 +01:00
history-clear-browser-fixture.mjs fix(alerts): discard pending history reads after clearing 2026-09-10 06:44:37 +01:00
hot-dev-bg.sh backend and governance: MCP contract, agent capabilities, API, and release-control 2026-06-23 17:26:15 +01:00
hot-dev.sh Keep hot-dev build temp on the configured Go temp volume 2026-08-31 22:11:38 +01:00
incident-browser-checks.md test(alerts): distinguish staged recovery edits from saved intent 2026-09-08 10:32:49 +01:00
incident-browser-fixture.mjs test(web): verify incident convergence after native tab suspension 2026-09-08 08:23:44 +01:00
incident-convergence-server.mjs test(web): verify incident convergence after native tab suspension 2026-09-08 08:23:44 +01:00
install-container-agent.sh Restore Docker agents to Hosts inventory 2026-07-23 22:06:56 +01:00
install-docker.sh Prepare v6.4.3-rc.1 release 2026-09-01 21:37:41 +01:00
install-go-toolchain.sh Advance release builds to Go 1.26.8 2026-09-04 07:20:28 +01:00
install-mcp.ps1 Fail closed when installing MCP binaries 2026-08-30 05:11:55 +01:00
install-mcp.sh fix(installer): verify checksums on FreeBSD without coreutils 2026-09-20 02:43:57 +01:00
install.ps1 Contain agent command authority 2026-08-29 22:12:41 +01:00
install.sh fix(installer): capture agent logs on FreeBSD/pfSense 2026-09-23 01:57:51 +01:00
npm-audit-retry.sh Keep positive npm advisory evidence fail-closed 2026-09-30 13:23:29 +01:00
package-helm-chart.sh
patrol_e2e_matrix.sh
prepare-release-container-context.sh Keep Windows agent update signatures addressable 2026-09-01 16:11:04 +01:00
pulse-auto-update.sh fix(updates): clear RETURN trap so a successful auto-update exits 0 2026-09-20 17:44:40 +01:00
release-go-test-events.py fix(release): mark store-history SLO measurement windows 2026-09-09 01:34:22 +01:00
release-preflight-worker.sh fix(release): give the rehearsal backend an explicit package timeout 2026-09-19 21:24:38 +01:00
release-resource-snapshot.py chore(release): retain bounded backend resource evidence 2026-09-07 16:47:55 +01:00
release_asset_common.sh Keep Windows agent update signatures addressable 2026-09-01 16:11:04 +01:00
release_build_targets.sh Separate agent remediation runtime 2026-08-29 23:48:28 +01:00
release_candidate_manifest.py Enforce exact release visual assets 2026-08-29 02:59:47 +01:00
release_ldflags.sh Require signed unified agent release assets 2026-04-22 02:00:29 +01:00
release_update_key.go Wire secure runtime RC qualification 2026-08-31 01:50:48 +01:00
remerge-parallel.sh
render_installers.go Fix RC3 backend release blockers 2026-05-01 21:36:28 +01:00
repo-boundary-paid-surface.allowlist Fix companion compatibility CI 2026-07-29 20:09:23 +01:00
repo-boundary-private-implementation.baseline Ratchet private boundary audit debt 2026-07-29 20:09:23 +01:00
require-safe-gh-attestation.sh Bind release activation to trusted provenance 2026-08-30 01:51:58 +01:00
run-ci-benchmarks.sh fix(ci): bind benchmark samples to executed binary hashes 2026-09-06 13:32:05 +01:00
run-native-pve-action-qualification.sh Add native PVE action qualification harness 2026-09-01 10:43:35 +01:00
run-release-backend-tests.sh Fix stable release backend partition 2026-08-29 01:15:59 +01:00
run-release-preflight.sh Accelerate release qualification with exact-SHA worker 2026-08-12 17:07:12 +01:00
run-secure-runtime-rootful-qualification.sh Tighten rootful runtime cleanup proof 2026-09-02 02:52:13 +01:00
run-secure-runtime-rootless-qualification.sh Give rootless qualification hosts unique identities 2026-09-01 21:18:24 +01:00
run_cloud_public_signup_smoke.sh Add Pulse Cloud public signup smoke 2026-04-23 23:09:10 +01:00
run_demo_public_browser_smoke.sh Add public browser smoke proof to demo workflows 2026-04-11 13:50:00 +01:00
run_hosted_staging_smoke.sh Auto-select hosted staging tenant 2026-04-15 12:23:57 +01:00
secure-runtime-rootful-runtime.sh Tighten rootful runtime cleanup proof 2026-09-02 02:52:13 +01:00
security_review_auth_credentials.sh Make security review baseline fail closed 2026-09-01 01:02:17 +01:00
session-handoff.sh
shard_go_tests.py Harden release backend cold-run qualification 2026-08-28 03:36:33 +01:00
standalone.manifest Require immutable attested releases 2026-08-29 19:59:04 +01:00
sync-production-config.sh
sync_chart_release_metadata.py fix(deploy): pin docs links to release refs 2026-03-28 21:32:11 +00:00
telemetry_adoption_report.py Report update channel and last update check outcome in telemetry (#2285) 2026-09-27 23:50:23 +01:00
test-vm-disk.sh
toggle-mock.sh Scale large-estate workload and Proxmox demo performance 2026-08-23 15:09:32 +01:00
trigger-release-dry-run.sh Soak release candidates for 24 hours before stable 2026-09-28 16:42:46 +01:00
trigger-release.sh Soak release candidates for 24 hours before stable 2026-09-28 16:42:46 +01:00
trigger-stable-patch.sh Bind release dispatches to the admitted commit 2026-09-02 02:28:14 +01:00
uninstall-sensor-proxy.sh fix(security): verify SSH hosts during proxy cleanup 2026-08-08 05:18:55 +01:00
validate-published-release.sh Authenticate every published installer 2026-08-31 04:55:15 +01:00
validate-release.sh Keep Windows agent update signatures addressable 2026-09-01 16:11:04 +01:00
verify-github-release-integrity.sh fix(release): reject ambiguous activation asset inventories 2026-09-05 15:43:23 +01:00
verify-release-container-images.sh Pin container provenance workflow revision 2026-09-01 09:56:14 +01:00
verify-release-helm-chart.sh Recover Helm Pages from attested OCI charts 2026-09-04 01:04:30 +01:00
verify-stable-container-aliases.sh Continuously verify stable container aliases 2026-08-30 13:55:41 +01:00
write_github_output.py Close runner output alias bypasses 2026-09-01 16:54:07 +01:00