fix(security): fail closed on ambiguous dependency-review HTTP responses - #1725
fix(security): fail closed on ambiguous dependency-review HTTP responses#1725seonghobae wants to merge 15 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fleet handoff — a second migration defect is now live-evidenced and belongs in the central consolidation contract/doctoring before #1725 leaves Draft. RCA: #1724's thin-caller replacements removed each caller workflow's permission envelope. A reusable workflow cannot elevate Exact RED evidence after immutable pinning (so mutable-ref resolution is no longer confounded):
Consumer GREEN repair is now applied without touching this owner branch: explicitly retain Owner-path acceptance: extend #1725's central contract/ADR/doctoring/example caller so every reusable Dependency Review caller is required to pass at least |
|
Fresh owner-path re-read confirms the permission handoff has advanced correctly to an explicit RED at Next owner GREEN should minimally update the canonical example/doctoring contract to include the two caller read permissions, preserve the existing non-200 fail-closed production repair, adopt protected |
seonghobae
left a comment
There was a problem hiding this comment.
Fresh-base owner handoff for exact head 403ca1c4de8b3e477b5a9b1c102188278286b2c8 (read-only; no source/ref/PR-state mutation): protected ContextualWisdomLab/.github/main is now 63bf49835da44aa8257eb76a92368e6485ae6e94 via #1728, while this Draft still records base b4eec000d21084accb736d289eb64cfd78e7a91a and is currently non-mergeable. Preserve the HTTP-non-200 fail-closed and least-privilege caller-permission RED/GREEN deltas; non-force reconcile with the live protected base, then re-run focused tests and every exact-current-head required/security/provenance check. Do not transfer the prior 403ca1c4… evidence across the new integration head. Consumers must continue to wait for the resulting protected-main immutable SHA and then pin that exact SHA; no @main, PR-head, skipped/cancelled/queued, or predecessor evidence is release authority.
|
Fresh Naruon reproduction confirms this PR's permission-envelope RCA on a fifth consumer. |
|
Current-main ancestry reconciliation rationale before write: protected I will therefore preserve both histories without force/rebase by creating a two-parent reconciliation commit with the current branch tree unchanged, parents |
|
Consumer owner-path acceptance from writable |
Evidence log — 2026-09-02Exact current head:
Gate decision: HOLD. Do not mark ready or merge until the branch is reconciled against current protected |
Security owner outcome
This Draft is the canonical
ContextualWisdomLab/.githubowner lane for the Dependency Review admission boundary. It now consolidates the valid security deltas from protected #1724 and predecessor diagnostic #1643 without weakening the pinned Dependency Review action or any sibling scanner.Three owner defects are repaired together:
contents: read+pull-requests: readpermission envelope that a called workflow cannot elevate itself;owner/namerepository identity before curl.Test-first and carryover lineage
The original #1725 RED/GREEN lineage remains intact for non-200 fail-closed behavior and caller permissions. Current successor commits add #1643's still-valid immutable-identity requirement test-first:
3736634f95bf132bbbe208ffc80103863fe3a7c1adds executable reusable-workflow regressions that require named/malformed revisions and malformed/dot-segment repository identities to fail before curl, while legalContextualWisdomLab/.githubreaches exactly one token-authenticated compare;b1e6263d9d9626b6cfd2046ce9147ab67867beecadds the corresponding reusable-workflow production validation;8b86c0d2c6b0186538db1ed263f7cb9d222f3ca1carries fix(security): validate immutable dependency-review identity on current main #1643's conflict-free bundledSecurity Scanidentity preflight onto the current owner tree without force-push or destructive rebase;ae128374a2e38e60ada8bf5e89a9c7a4137f864frecords the decisive A/B evidence and unified security invariants in canonical doctoring;58a0b4c8ecc3073a64bd91457101229a21f020d4adds a dedicated bundled-scan regression so the carried validation cannot silently disappear.The temporary #1643 canary itself is deliberately not part of this publishable successor.
Decisive A/B evidence from #1643
Exact-head canary run
33589436750, job100120235906, checked outa6a2759640e6aa1d1e1219e1cd7aacdeffef32c0and compared exact basebb14b014eee31e6abdb5d2fffbb805aa29420eacto that head forContextualWisdomLab/.github.404, curl exit0;contents: read+pull-requests: read: HTTP200, curl exit0.Therefore an anonymous response is not an availability authority. The least-privilege job token is the supported comparison boundary, and non-200 authenticated results remain fail-closed.
Current protected-main relationship — 2026-09-02
Protected base for this exact head is
main@78271917b526469c559fa75cb5ee39426e5494d1. Exact current head is58a0b4c8ecc3073a64bd91457101229a21f020d4.Fresh comparison is
ahead/behind_by=0. The effective protected-main-relative delta is exactly six owner paths:.github/workflows/dependency-review.yml;.github/workflows/security-scan.yml;docs/doctoring/dependency-review-fail-closed-permission-envelope.md;GitHub reports the PR Draft and mechanically mergeable. No temporary source-fix or A/B canary workflow is present in this successor.
Consumer evidence and release boundary
Before caller permission repair, immutable reusable-workflow consumers such as
ContextualWisdomLab/newsdom-api#784@1623977e6c37c78cb1a94a7a48c48f6d02cac86c(33622976911) andContextualWisdomLab/mightyETL#330@65efdf7b4064df5b9811c0403defb707e6efbc02(33623035969) terminatedstartup_failurewith zero jobs. After explicit caller permissions, fresh exact heads materialized Dependency Review runs in newsdom-api, mightyETL, scopeweave and Argos.After this PR reaches protected main through ordinary protection, consumers must pin the reusable workflow to that immutable protected-main SHA. No caller returns to
@main, a PR head, or another mutable owner ref.Exact-head gate
The current source head invalidates all predecessor check/review evidence. Exact-head runs are newly queued/pending: OSV
33637850661, Secret Scan33637849083, Security Scan33637849313, CodeQL33637849320, Scorecard33637849319, SBOM33637849219, SAST33637849226, and Python Security33637849275. They are non-passing until terminal.Keep Draft and ADR-0025 Proposed until this unchanged head has terminal required checks, substantive-clean current reviews/threads, current base/mergeability and ordinary protected admission. No administrator bypass, self-approval, scanner substitution, predecessor-evidence transfer, mutable workflow pin, or 403-as-success is authorized.
Refs #810, #1150, #1643, #1724, #1728, #1731, #1734.