fix(security): fail closed on ambiguous dependency-review HTTP responses - #1725
fix(security): fail closed on ambiguous dependency-review HTTP responses#1725seonghobae wants to merge 19 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fleet handoff — a second migration defect is now live-evidenced and belongs in the central consolidation contract/doctoring before #1725 leaves Draft. RCA: #1724's thin-caller replacements removed each caller workflow's permission envelope. A reusable workflow cannot elevate Exact RED evidence after immutable pinning (so mutable-ref resolution is no longer confounded):
Consumer GREEN repair is now applied without touching this owner branch: explicitly retain Owner-path acceptance: extend #1725's central contract/ADR/doctoring/example caller so every reusable Dependency Review caller is required to pass at least |
|
Fresh owner-path re-read confirms the permission handoff has advanced correctly to an explicit RED at Next owner GREEN should minimally update the canonical example/doctoring contract to include the two caller read permissions, preserve the existing non-200 fail-closed production repair, adopt protected |
seonghobae
left a comment
There was a problem hiding this comment.
Fresh-base owner handoff for exact head 403ca1c4de8b3e477b5a9b1c102188278286b2c8 (read-only; no source/ref/PR-state mutation): protected ContextualWisdomLab/.github/main is now 63bf49835da44aa8257eb76a92368e6485ae6e94 via #1728, while this Draft still records base b4eec000d21084accb736d289eb64cfd78e7a91a and is currently non-mergeable. Preserve the HTTP-non-200 fail-closed and least-privilege caller-permission RED/GREEN deltas; non-force reconcile with the live protected base, then re-run focused tests and every exact-current-head required/security/provenance check. Do not transfer the prior 403ca1c4… evidence across the new integration head. Consumers must continue to wait for the resulting protected-main immutable SHA and then pin that exact SHA; no @main, PR-head, skipped/cancelled/queued, or predecessor evidence is release authority.
|
Fresh Naruon reproduction confirms this PR's permission-envelope RCA on a fifth consumer. |
|
Current-main ancestry reconciliation rationale before write: protected I will therefore preserve both histories without force/rebase by creating a two-parent reconciliation commit with the current branch tree unchanged, parents |
|
Consumer owner-path acceptance from writable |
Evidence log — 2026-09-02Exact current head:
Gate decision: HOLD. Do not mark ready or merge until the branch is reconciled against current protected |
|
Fresh Context Fabric consumer evidence confirms this owner lane is still required, but the branch must be reconciled onto current protected
The live owner branch is now |
|
Fresh consumer correction, 2026-09-05: This materially extends #1725's older A/B evidence: authenticated 200 is not universal across current required-workflow consumers. I did not force-restack this deeply diverged branch. Current-main successor Draft #1873 starts from protected |
|
SOURCE WRITER CLAIM — reverse restack PR #1995 is retired because its A detached preflight merge completed without conflict. Its candidate tree differs from current protected main in exactly the six canonical #1725 owner paths; focused dependency-review/security contracts are |
Retire the reverse-PR restack path and preserve the six dependency-review owner paths while recording protected main as the second parent.
|
SOURCE WRITER RELEASE — exact head
The first focused invocation named one nonexistent test file and exited before collecting tests; it was a command-selection error, not a source failure. The corrected exact-tree focused suite and full suite above are the claimed evidence. Fresh hosted state is |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head execution receipt: ordinary parents 0bb8f7c06cb2ce291101e7014afe90bef0fe40c4 + protected main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db, tree bb57a09a8677536221b016cc3339cf258bcbb1de. The protected CodeQL #2028 delta was adopted without entering this PR's six-path Dependency Review diff. Local GREEN: focused 20 passed; full 3001 passed, 1 skipped, 21 subtests; git diff --check PASS. Hosted exact-head gates remain nonterminal, so this is evidence only, not approval or merge authorization.
|
Fresh consumer evidence from Exact consumer evidence:
No LineageWeave caller-side skip/fallback or gate weakening was added. After #1725 reaches protected |
|
Fresh consumer evidence from |
|
Second independent LineageWeave consumer confirms the same admission failure is systemic rather than specific to #983. On |
|
Fresh independent consumer evidence from This is not a LineageWeave source/scanner finding: the same exact head has SAST GREEN and OSV/Scorecard/Trivy lanes succeeding; no leaf substitute scanner or synthetic receipt was added. Treat this as another consumer acceptance case for #1725: after the owner repair reaches immutable protected main and the consumer pins it, the same exact authenticated compare must return HTTP 200 and Dependency Review must actually execute before the consumer gate can be GREEN. |
|
Fresh consumer evidence from LineageWeave keeps this owner prerequisite live. |
|
Fresh LineageWeave consumer evidence from Security Scan run Keep this as consumer RED for the canonical owner repair/release path: after owner integration, the acceptance target remains an authenticated HTTP 200 compare plus an actually executed Dependency Review verdict on a consumer pinned to the immutable released owner revision. |
|
Fresh LineageWeave consumer evidence on exact |
Current integration receipt — 2026-09-08
4ccb21d8ace608f28d11d72589e5deb78add3a33.main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db.0bb8f7c06cb2ce291101e7014afe90bef0fe40c4plus protected main; exact treebb57a09a8677536221b016cc3339cf258bcbb1de.20 passed, full3001 passed · 1 skipped · 21 subtests, diff check PASS.12 queued · 1 skipped; no queued or skipped result is counted as a security verdict.Security owner outcome
This Draft is the canonical
ContextualWisdomLab/.githubowner lane for the Dependency Review admission boundary. It now consolidates the valid security deltas from protected #1724 and predecessor diagnostic #1643 without weakening the pinned Dependency Review action or any sibling scanner.Three owner defects are repaired together:
contents: read+pull-requests: readpermission envelope that a called workflow cannot elevate itself;owner/namerepository identity before curl.Test-first and carryover lineage
The original #1725 RED/GREEN lineage remains intact for non-200 fail-closed behavior and caller permissions. Current successor commits add #1643's still-valid immutable-identity requirement test-first:
3736634f95bf132bbbe208ffc80103863fe3a7c1adds executable reusable-workflow regressions that require named/malformed revisions and malformed/dot-segment repository identities to fail before curl, while legalContextualWisdomLab/.githubreaches exactly one token-authenticated compare;b1e6263d9d9626b6cfd2046ce9147ab67867beecadds the corresponding reusable-workflow production validation;8b86c0d2c6b0186538db1ed263f7cb9d222f3ca1carries fix(security): validate immutable dependency-review identity on current main #1643's conflict-free bundledSecurity Scanidentity preflight onto the current owner tree without force-push or destructive rebase;ae128374a2e38e60ada8bf5e89a9c7a4137f864frecords the decisive A/B evidence and unified security invariants in canonical doctoring;58a0b4c8ecc3073a64bd91457101229a21f020d4adds a dedicated bundled-scan regression so the carried validation cannot silently disappear.The temporary #1643 canary itself is deliberately not part of this publishable successor.
Decisive A/B evidence from #1643
Exact-head canary run
33589436750, job100120235906, checked outa6a2759640e6aa1d1e1219e1cd7aacdeffef32c0and compared exact basebb14b014eee31e6abdb5d2fffbb805aa29420eacto that head forContextualWisdomLab/.github.404, curl exit0;contents: read+pull-requests: read: HTTP200, curl exit0.Therefore an anonymous response is not an availability authority. The least-privilege job token is the supported comparison boundary, and non-200 authenticated results remain fail-closed.
Current protected-main relationship — 2026-09-07
Protected source/base is
main@c9052e607e5f3cc76e73207e7786b21500721b79; exact owner head is0bb8f7c06cb2ce291101e7014afe90bef0fe40c4. The direct ordinary adoption records predecessorc2e8ab0e535245f8f53801ad6a11e107fe492341and protected main as its two parents. The exact tree differs from main in only the six owner paths listed above. Reverse PR #1995 is closed and no longer participates in acceptance.Consumer evidence and release boundary
Before caller permission repair, immutable reusable-workflow consumers such as
ContextualWisdomLab/newsdom-api#784@1623977e6c37c78cb1a94a7a48c48f6d02cac86c(33622976911) andContextualWisdomLab/mightyETL#330@65efdf7b4064df5b9811c0403defb707e6efbc02(33623035969) terminatedstartup_failurewith zero jobs. After explicit caller permissions, fresh exact heads materialized Dependency Review runs in newsdom-api, mightyETL, scopeweave and Argos.After this PR reaches protected main through ordinary protection, consumers must pin the reusable workflow to that immutable protected-main SHA. No caller returns to
@main, a PR head, or another mutable owner ref.Exact-head gate
All predecessor check/review evidence is invalidated. The authoritative current-head materialization is the live tally in the receipt above; exact-head approval remains absent, and nonterminal/failed gates are not transferable. Keep Draft and ADR-0025 Proposed until this unchanged successor has terminal passing required checks, substantive-clean current reviews/threads, current base/mergeability, and ordinary protected admission.
Refs #810, #1150, #1643, #1724, #1728, #1731, #1734.