Skip to content

security(ci): close .DotSettings gap in pr.yaml protected-file guard - #379

Merged
Chris-Wolfgang merged 1 commit into
mainfrom
claude/reverent-dijkstra-14800f
Aug 14, 2026
Merged

Chris-Wolfgang merged 1 commit into
mainfrom
claude/reverent-dijkstra-14800f

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Summary

  • The InspectCode job's own comment already flags .DotSettings as a protected-config vector:

    a malicious PR could ship a permissive .editorconfig / BannedSymbols.txt / .DotSettings that would silence InspectCode findings on the PR's own code.

  • But *.DotSettings was missing from every config_files=(...) array — so the code did not do what the comment said. A PR could therefore ship its own .DotSettings suppression file and InspectCode would honor it, since InspectCode's noise floor is tuned via .DotSettings at the repo root (see chore(security): InspectCode noise-floor .DotSettings (#361) #378).
  • Adds *.DotSettings to all five bash arrays plus the Windows-stage pwsh $globPatterns, and extends the Detect protected configuration file changes regex so a PR that touches its own .DotSettings gets the same maintainer-review gate as .editorconfig / .globalconfig / .ruleset / workflow files already do.

Notes for merge

  • This PR modifies a workflow file, so Detect .NET Projects will fail with the "protected config file changed" gate. Admin bypass required — the pattern is a one-file protected-file-PR-split; this PR is the split (nothing else in it).
  • Once merged, the fleet's canonical pr.yaml in Chris-Wolfgang/repo-template needs the same edit so downstream repos pick it up on the next template-drift sweep (follow-up).

Test plan

  • Admin-bypass merge to main
  • On the next PR that touches .DotSettings (e.g. a follow-up to chore(security): InspectCode noise-floor .DotSettings (#361) #378), confirm Detect .NET Projects fails with .DotSettings in the changed-files list
  • Confirm InspectCode job logs show ✓ Copying <file>.DotSettings from main branch on any PR where main has a .DotSettings

🤖 Generated with Claude Code

The InspectCode job's comment already flagged .DotSettings as a
protected-config vector (line 287: 'a malicious PR could ship a
permissive .editorconfig / BannedSymbols.txt / .DotSettings that
would silence InspectCode findings'), but *.DotSettings was missing
from the config_files array actually overwritten from main. A PR
could therefore ship its own .DotSettings suppression file to silence
InspectCode warnings on its own code, since InspectCode's noise
floor is tuned via .DotSettings at the repo root.

Add "*.DotSettings" to every fetch-from-main config array (five
bash arrays and the Windows-stage pwsh globPatterns) and extend the
Detect protected configuration file changes regex to catch it, so a
PR that touches its own .DotSettings gets flagged for maintainer
review just like .editorconfig, .globalconfig, .ruleset, and
workflow files already do.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 13, 2026 21:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants