-
Notifications
You must be signed in to change notification settings - Fork 0
fix(osv): preserve immutable direct-source provenance #1158
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
seonghobae
wants to merge
72
commits into
main
Choose a base branch
from
fix/osv-direct-source-provenance-1096
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
72 commits
Select commit
Hold shift + click to select a range
654e554
test(osv): define direct-source provenance contracts
seonghobae 327f9c7
ci(osv): exercise direct-source provenance contract
seonghobae 93dd991
fix(osv): reconcile exact immutable source evidence
seonghobae 00abb82
docs(osv): explain direct-source provenance evidence
seonghobae 123d9d2
ci(osv): preserve provenance before vulnerability verdict
seonghobae 80fd3fd
ci(osv): bind policy checkout to governed source
seonghobae 03254d7
test(osv): bind reconciliation ahead of reporter
seonghobae 2b7f71d
test(osv): reproduce live nested advisory shape
seonghobae 9b95378
fix(osv): read authoritative nested affected range
seonghobae f2a9419
test(osv): reject package-key tarball disagreement
seonghobae 42845bb
ci(osv): require full suite and branch coverage
seonghobae 9d33c40
test(osv): cover every fail-closed provenance branch
seonghobae 003b357
fix(osv): fail closed on malformed source ports
seonghobae 78ae8a0
test(osv): assert exact CLI success code
seonghobae 29af209
fix(ci): keep provenance quality workflow PR-only
seonghobae c573b35
fix(osv): fail closed on ambiguous provenance
seonghobae c3636cc
Merge remote-tracking branch 'origin/main' into HEAD
seonghobae e2c0031
fix(osv): reject malformed UTF-8 inputs safely
seonghobae d1da605
fix(osv): exit cleanly on malformed text input
seonghobae 73bb8c7
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] f285fd7
test: document OSV provenance cases
seonghobae 915a528
Merge branch 'main' into fix/osv-direct-source-provenance-1096
seonghobae c6c2684
fix(security): read OSV inputs without symlink races
seonghobae fe27160
test(security): cover secure OSV input branches
seonghobae 75d7f5f
style(test): combine secure input contexts
seonghobae a0fbba8
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] 9f46401
fix(osv): accept verified empty scan documents
seonghobae 6a4e63a
docs: close coordinator docstring gate
seonghobae 0f2e4c9
chore(osv): satisfy reconciler lint contract
seonghobae 6e93fd0
fix(osv): parse pnpm package provenance safely
seonghobae 6ea77b1
Merge protected main into OSV direct-source provenance
seonghobae 3a619b5
fix(security): pin pip-audit pip below vulnerability
seonghobae ad46744
fix(osv): distinguish findings from scanner failure
seonghobae a93d086
fix(security): retain fixed pip-audit toolchain
seonghobae d02d57e
fix(security): regenerate pip audit lock provenance
seonghobae f031579
chore(security): keep pip lock repair in its owner branch
seonghobae 67f3064
Merge branch 'main' into fix/osv-direct-source-provenance-1096
seonghobae 843d874
test: align scheduler gate with dispatch concurrency
seonghobae a7fb512
docs(security): clarify per-scan OSV evidence ownership
seonghobae acbd253
test: track scheduler concurrency contract
seonghobae 7a171bc
chore(osv): restore Strix contract to owner lane
seonghobae 9b44801
test(scheduler): track current dispatch concurrency
seonghobae 7449aaf
chore(osv): keep Strix assertions on canonical owner
seonghobae 10f1ccd
test(security): require supported OSV output flags
seonghobae db6dee6
fix(security): use supported OSV output arguments
seonghobae c24ce16
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] 1eaba56
test(scheduler): preserve dispatch concurrency contract
seonghobae 092d838
chore(osv): restore canonical Strix ownership
seonghobae fca5cd1
test(scheduler): align quick gate with canonical concurrency
seonghobae eb7efe5
ci: refresh pip audit runtime
seonghobae c45a776
chore(osv): restore canonical pip lock ownership
seonghobae f61a879
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] 4748ced
fix(osv): report malformed evidence cleanly
seonghobae 4e1102b
Merge branch 'main' into fix/osv-direct-source-provenance-1096
seonghobae 2cc5427
Merge protected main into OSV provenance repair
seonghobae 6a92e1c
fix(osv): pin immutable SheetJS artifact integrity
seonghobae 10ee81c
fix(security): trust protected policy on self-scan
seonghobae e61fb11
fix(osv): preserve raw evidence during policy bootstrap
seonghobae 3741f69
merge(main): refresh OSV provenance owner
seonghobae 9736108
fix(osv): report atomic evidence write failures cleanly
seonghobae 88b6859
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] abada26
Merge protected main into fix/osv-direct-source-provenance-1096
seonghobae 3212348
Merge protected main into OSV direct-source provenance
seonghobae 05b1f25
docs(osv): clarify inclusive affected bounds
seonghobae 79bcded
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] 9eb3659
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] 8d3f84a
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] 5addc92
Merge protected main into OSV provenance owner
seonghobae 1283b98
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] c537afe
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] ebe39ac
Merge branch 'main' into fix/osv-direct-source-provenance-1096
opencode-agent[bot] e2b31d8
Merge branch 'main' into fix/osv-direct-source-provenance-1096
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,63 @@ | ||
| name: OSV Direct Source Quality CI | ||
|
|
||
| on: | ||
| pull_request: | ||
| branches: [main] | ||
| paths: | ||
| - '.github/workflows/security-scan.yml' | ||
| - '.github/workflows/osv-direct-source-quality-ci.yml' | ||
| - 'scripts/ci/osv_direct_source_reconcile.py' | ||
| - 'tests/test_osv_direct_source_reconcile.py' | ||
| - 'docs/doctoring/osv-direct-source-provenance.md' | ||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: osv-direct-source-quality-${{ github.event.pull_request.number || github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| provenance-contract: | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 15 | ||
| steps: | ||
| - name: Checkout exact source revision | ||
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| with: | ||
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | ||
| persist-credentials: false | ||
| - name: Set up Python | ||
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | ||
| with: | ||
| python-version: '3.14' | ||
| - name: Install exact hash-verified quality dependencies | ||
| env: | ||
| PIP_DISABLE_PIP_VERSION_CHECK: '1' | ||
| PIP_NO_INPUT: '1' | ||
| shell: bash --noprofile --norc -e -o pipefail {0} | ||
| run: | | ||
| cat >"${RUNNER_TEMP}/osv-provenance-quality-requirements.txt" <<'EOF' | ||
| coverage==7.15.2 --hash=sha256:b9a6367e4aff723e8ee8190836836124284e8fcd4265e307c844010cfa074f3f | ||
| iniconfig==2.1.0 --hash=sha256:9deba5723312380e77435581c6bf4935c94cbfab9b1ed33ef8d238ea168eb760 | ||
| packaging==26.2 --hash=sha256:5fc45236b9446107ff2415ce77c807cee2862cb6fac22b8a73826d0693b0980e | ||
| pluggy==1.6.0 --hash=sha256:e920276dd6813095e9377c0bc5566d94c932c33b27a3e3945d8389c374dd4746 | ||
| pygments==2.20.0 --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 | ||
| pytest==9.1.1 --hash=sha256:37a86b45efb9a47a61a36449063e8e18d0cab3161329fc099eb21783169c4f0c | ||
| EOF | ||
| python -m pip install \ | ||
| --only-binary=:all: \ | ||
| --require-hashes \ | ||
| -r "${RUNNER_TEMP}/osv-provenance-quality-requirements.txt" | ||
| - name: Verify full central suite and provenance coverage | ||
| shell: bash --noprofile --norc -e -o pipefail {0} | ||
| run: | | ||
| test "$(git rev-parse HEAD)" = "${{ github.event.pull_request.head.sha || github.sha }}" | ||
| python -m coverage run --branch -m pytest --import-mode=importlib tests -q | ||
| python -m coverage report \ | ||
| --include='scripts/ci/osv_direct_source_reconcile.py' \ | ||
| --show-missing \ | ||
| --fail-under=100 | ||
|
seonghobae marked this conversation as resolved.
|
||
| python -m compileall -q \ | ||
| scripts/ci/osv_direct_source_reconcile.py \ | ||
| tests/test_osv_direct_source_reconcile.py | ||
| git diff --exit-code | ||
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.