Compare commits
4 Commits
guard-drop
...
guard-exem
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0fb2df11a6 | ||
| 44a1800eff | |||
|
|
dc1cfbf044 | ||
| 61776ce021 |
@@ -92,3 +92,39 @@ allow:
|
||||
approved_by: windy-hub
|
||||
approved_on: 2026-10-02
|
||||
expires: 2026-12-31
|
||||
|
||||
- repo: windy-registry
|
||||
paths: ["tools/r2-provision.sh"]
|
||||
matches: ['http://localhost:8788']
|
||||
reason: "Dev origin in an R2 bucket CORS rule, not a call to the Talk engine (Hub 10-02)."
|
||||
exemption: owner-approved
|
||||
approved_by: windy-hub
|
||||
approved_on: 2026-10-02
|
||||
expires: 2026-12-31
|
||||
|
||||
- repo: windytalk
|
||||
paths: ["engine/*", "scripts/stress/*", "scripts/veron/*"]
|
||||
matches: [':(8791|8788|8794)']
|
||||
reason: "Talk's own voice engines (server, systemd unit, stress scripts); to be placed behind Mind per Mind's audit plan. NOT compute-door: a real bypass being fixed (Hub 10-02)."
|
||||
exemption: owner-approved
|
||||
approved_by: windy-hub
|
||||
approved_on: 2026-10-02
|
||||
expires: 2026-12-31
|
||||
|
||||
- repo: windytalk
|
||||
paths: ["scripts/run-client.sh"]
|
||||
matches: [':(8791|8788|8794)']
|
||||
reason: "Dev client launcher: 127.0.0.1:8788 is an ssh -L tunnel to the dev engine ON VERON (not the user's machine), so engine-side; dev-only, not shipped. To be placed behind Mind per Mind's audit plan (Windy Talk, Hub 10-02)."
|
||||
exemption: owner-approved
|
||||
approved_by: windy-hub
|
||||
approved_on: 2026-10-02
|
||||
expires: 2026-12-31
|
||||
|
||||
- repo: windytalk
|
||||
paths: ["apps/desktop/renderer/index.html"]
|
||||
matches: [':(8791|8788|8794)']
|
||||
reason: "Display-only fallback label in the settings panel (cfg.engineUrl || default); connects to nothing. The shipped client defaults to the public engine on Veron, never local inference (Windy Talk, Hub 10-02)."
|
||||
exemption: owner-approved
|
||||
approved_by: windy-hub
|
||||
approved_on: 2026-10-02
|
||||
expires: 2026-12-31
|
||||
|
||||
Reference in New Issue
Block a user