Release ShadowFrog codebase - #4
Merged
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 8 commits intoJun 18, 2026
Merged
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 8 commits into
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 8 commits into
Conversation
Publish the ShadowFrog skills package, installer, hook templates, examples, evaluation documentation, tests, and release validation scripts to microsoft/ShadowFrog. Use hook-templates/ as the source package directory for bundled hook configs/scripts to satisfy public-repo path rules while preserving installed .github/hooks/ and .claude/hooks/ behavior. Excluded internal repository policy/compliance files and public-repo workflow files, and preserved the public Microsoft SECURITY.md template already present in the target repository. Validation: no internal reference/secrets scan matches; JSON and SKILL frontmatter parse; full pytest 1063 passed; direct Copilot/Claude install smoke tests matched hook templates byte-for-byte; hook fail-open guard passes; shellcheck passes; git diff --check passes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Link the public README to the Shadow-Frog launch blog post on debug-gym. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Replace the stale /shadowfrog/ URL with the published /shadow-frog/ permalink in RESPONSIBLE_AI.md. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Avoid a one-file top-level scripts directory by colocating check-hook-failopen.py with the hook templates it validates. Update docs and tests to reference hook-templates/check-hook-failopen.py. Validation: direct checker invocation passes; focused hook tests pass. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Normalize historical hook validation wording for the public release layout: refer to static guard and hook-template scripts rather than CI guard or top-level hooks source paths. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add required GitHub Actions workflows for pytest and shellcheck/fail-open validation in microsoft/ShadowFrog. The shellcheck workflow uses hook-templates/ as the source hook-template directory while install.sh continues to install hooks into .github/hooks/ and .claude/hooks/. Validation: workflow YAML parsed; full pytest passed; shellcheck/fail-open guard passed locally. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Enable weekly Dependabot updates for Python dev dependencies and GitHub Actions workflows in the public ShadowFrog repo. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add a required GitHub code scanning workflow for the public ShadowFrog repository. The workflow analyzes Python on pull requests, pushes to main, and a weekly schedule. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Xingdi (Eric) Yuan (xingdi-eric-yuan)
deleted the
users/eryua/release-shadowfrog-main
branch
June 18, 2026 22:32
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation