Skip to content

Release ShadowFrog codebase - #4

Merged
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 8 commits into
mainfrom
users/eryua/release-shadowfrog-main
Jun 18, 2026
Merged

Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 8 commits into
mainfrom
users/eryua/release-shadowfrog-main

Conversation

@xingdi-eric-yuan

Copy link
Copy Markdown
Collaborator

Summary

  • Publish the ShadowFrog skills package, installer, hook templates, examples, evaluation docs, tests, and release validation scripts.
  • Use hook-templates/ as the source package directory for bundled hook configs/scripts to satisfy public repository path rules while preserving installed .github/hooks/ and .claude/hooks/ behavior.
  • Exclude internal repository policy/compliance files and public-repo workflow files; preserve the Microsoft SECURITY.md template that already existed in the target repo.

Validation

  • No internal reference/secrets scan matches.
  • JSON and SKILL frontmatter parse.
  • Full pytest: 1063 passed.
  • Direct Copilot and Claude install smoke tests: installed hook files match hook-templates byte-for-byte and hook scripts exit 0.
  • Hook fail-open guard passes.
  • Shellcheck passes.
  • git diff --check passes.

Publish the ShadowFrog skills package, installer, hook templates, examples, evaluation documentation, tests, and release validation scripts to microsoft/ShadowFrog.

Use hook-templates/ as the source package directory for bundled hook configs/scripts to satisfy public-repo path rules while preserving installed .github/hooks/ and .claude/hooks/ behavior.

Excluded internal repository policy/compliance files and public-repo workflow files, and preserved the public Microsoft SECURITY.md template already present in the target repository.

Validation: no internal reference/secrets scan matches; JSON and SKILL frontmatter parse; full pytest 1063 passed; direct Copilot/Claude install smoke tests matched hook templates byte-for-byte; hook fail-open guard passes; shellcheck passes; git diff --check passes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Link the public README to the Shadow-Frog launch blog post on debug-gym.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Replace the stale /shadowfrog/ URL with the published /shadow-frog/ permalink in RESPONSIBLE_AI.md.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Avoid a one-file top-level scripts directory by colocating check-hook-failopen.py with the hook templates it validates.

Update docs and tests to reference hook-templates/check-hook-failopen.py. Validation: direct checker invocation passes; focused hook tests pass.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Normalize historical hook validation wording for the public release layout: refer to static guard and hook-template scripts rather than CI guard or top-level hooks source paths.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add required GitHub Actions workflows for pytest and shellcheck/fail-open validation in microsoft/ShadowFrog.

The shellcheck workflow uses hook-templates/ as the source hook-template directory while install.sh continues to install hooks into .github/hooks/ and .claude/hooks/.

Validation: workflow YAML parsed; full pytest passed; shellcheck/fail-open guard passed locally.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Enable weekly Dependabot updates for Python dev dependencies and GitHub Actions workflows in the public ShadowFrog repo.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add a required GitHub code scanning workflow for the public ShadowFrog repository. The workflow analyzes Python on pull requests, pushes to main, and a weekly schedule.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@xingdi-eric-yuan
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged commit a18c457 into main Jun 18, 2026
5 checks passed
@xingdi-eric-yuan
Xingdi (Eric) Yuan (xingdi-eric-yuan) deleted the users/eryua/release-shadowfrog-main branch June 18, 2026 22:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants