|
caveman: disable on live host + SEC-017 + fail-closed compress guardrails
Council-reviewed follow-through on the caveman plugin (operator accepted the recommendations). Three gated deliverables: 1. DISABLED on the live host: enabledPlugins."caveman@caveman"=false at user (~/.claude, uncommitted) + committed repo scope; env CAVEMAN_DEFAULT_MODE=off retained; marketplace kept for deliberate re-enable. Stops the per-turn third-party hook execution (which ran regardless of mode=off) at next session start. 2. SEC-017 opened (docs/security-ledger.md): supply-chain re-verify obligation pinning SHA 0d95a81 + self-remeasured baseline hashes; register = OPS (no D-number per GA-R3; precedent D-129). Open SEC 12->13, reconciled at Stage 4 close (not an L10 trigger; CURRENT-STATE untouched). 3. Guardrails: repo-lint L11 FAILs on any *.original.md (caveman-compress residue), opt-out marker + harness T42-T44 (45/45 PASS); .claude/settings.json deny on Bash(*python3 -m scripts*)+Bash(*caveman-compress*); CLAUDE.md "Tooling guardrails" prohibiting the compressor against any repo-tracked prose. Rejected the proposed plugin-hash-baseline-in-repo-lint (layering violation; drift belongs in the SEC-017 re-verify duty). Harness-config + governance only; no cloud mutation. repo-lint 0 fail; gauntlet ALL GREEN (77). Changelog: docs/changelog-20260724-caveman-disable.md. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw |
|---|
|
|
| .claude/settings.json |
|---|
| CLAUDE.md |
|---|
| docs/changelog-20260724-caveman-disable.md 0 → 100644 |
|---|
| docs/security-ledger.md |
|---|
| scripts/repo-lint.sh |
|---|
| scripts/repo_lint.py |
|---|
| tests/repo-lint/run-tests.sh |
|---|