← Back to TrustBridge

INSPECT THE WORK · 09 OCTOBER 2026

Proof you can follow.

Source code, real GitLab jobs, and an intentionally blocked merge request. Each link shows a specific result. Native Duo execution is the next unverified milestone.

01 / SOURCE

Open code. Original history.

TrustBridge extends the MIT-licensed ContextFirewall project. The GitLab repository retains the original commits and distinguishes the new context, policy and review code.

Read the public GitLab source ↗

02 / GITLAB CI

Checks that actually ran.

The main-branch pipeline at commit fb8ec45 passed 94 Python tests, 24 Node tests, security scan, lint, context auditing and policy enforcement. All eight jobs succeeded, including container packaging. These are advisory application checks; they grant no permission to merge or deploy.

Inspect the passing pipeline ↗

03 / A REAL FAILURE CASE

Make the unsafe change visible.

Draft MR !1 deliberately removes the required security scan from the candidate release policy. CI still contains the security job and the enforcement code. The context audit retained one accepted policy and one excluded stale observation. The policy gates then rejected the candidate with MANDATORY_CHECK_MISSING and saved a minimal repair proposal. Tests and the security scan passed; policy enforcement remained blocked.

This is a controlled demonstration on an unmerged branch, prepared by Codex. It is not a Duo-generated repair or a record of human approval.

Inspect the demonstration MR ↗

Download the context and repair proposal JSON ↗

Follow its actual pipeline result ↗

04 / BUILT AND TESTED

A runnable container.

GitLab built the actual non-root image and exercised its HTTP service with a read-only filesystem and no external network. All twelve scenario variants passed, and health matched the built commit. The image archive, digest and smoke receipt are retained for inspection. This package has not been authorized for production release.

Read the container smoke receipt ↗

Inspect the package job and artifacts ↗

05 / STILL TO PROVE

The release story is unfinished.

Native Duo

Register and execute the custom flow, capture real reject, modify and approve decisions, and show the resulting repair commit.

Independent verification

The local controller works against a pinned baseline. Hosted controller membership, agent write denial and the updated candidate boundary still need verification.

Deployment and recording

The public site is live on Cloudflare. A controller-authorized release and end-to-end demo recording remain outstanding. Google Cloud is optional and has not been used.

No completed hackathon submission, autonomous release, or production safety certification is claimed.

Try the public reviewer.

Audit an MR ↗

Or explore clearly labeled sample scenarios.