fix(security): keep every CodeQL Action phase on one revision - #780
fix(security): keep every CodeQL Action phase on one revision#780seonghobae wants to merge 25 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
/oc Refetch the live pull request and abort without writing unless its exact head is |
Rebuild the PR from protected develop with only the atomic CodeQL lifecycle update, its test-first contract, doctoring record, and changelog entry. Remove unrelated PDF.js and npm lockfile drift from this branch.
8d932e5 to
efd875b
Compare
|
Exact-head triage at |
|
@opencode-agent Review the exact current head |
Update every CodeQL lifecycle phase and SARIF uploader to the verified upstream v4.37.7 commit, refresh the regression contract, changelog, and doctoring, and record the v2.26.3 bundle update. Preserve immutable SHA pinning and the existing atomic-version policy.
|
Queued @opencode-agent for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
3 similar comments
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
2 similar comments
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
@opencode-agent Repair the exact current-head Ruff formatter blocker on the existing |
|
/oc Refetch PR #780 and abort without writing unless the live branch is Systematic-debugging evidence for this exact head:
The hand-edited layout on Verification acceptance on the successor exact head: focused |
|
@opencode-agent Repair only the current exact-head formatter blocker on the existing Authoritative current-head RED evidence is CI run Run the repository-pinned formatter ( |
Ordinary-merge the current protected develop lineage into the canonical CodeQL lifecycle lane while making the next coordinated repair executable. The deterministic RED contract requires CodeQL Action v4.37.9 across every checked-in phase, the repository CI/CD Dependabot label, and pull-request Scorecard evidence that checks out trusted normalization code from the base. Production workflows are intentionally unchanged in this commit. No predecessor check, review, or approval evidence transfers.
Advance every checked-in CodeQL Action phase to the same immutable v4.37.9 commit, preserve Scorecard pull-request evidence behind a trusted base-SHA normalization checkout, and route GitHub Actions Dependabot updates to the existing area: ci-cd taxonomy. The preceding commit holds the deterministic RED contracts; this commit supplies the smallest owning workflow/config fix. The upstream v4.37.9 tag resolves to cdf488f595d80d6e07e03d4674febd5ab45fa938 and is unsigned; no signed-tag claim is made. Split or predecessor checks and reviews do not transfer.
|
Succession update for #1144: fresh organization ruleset |
Outcome
Keep BandScope's checked-in CodeQL lifecycle under one canonical supply-chain owner instead of merging
init,autobuild,analyze, andupload-sarifDependabot fragments independently. This branch also absorbs the unique repository-control behavior that had accumulated in competing PR #1026: valid Dependabot CI/CD taxonomy and pull-request OpenSSF Scorecard evidence with trusted normalization code.Fresh exact identity
develop@749511c3ad4000090048718f685c6bee6b3d2c25.fix/codeql-action-consistency-v4-37-6.823a66200f7a9c846147d3632cc167c1c8f08c65.develop:ahead_by=18,behind_by=0, merge base exactly749511c3ad4000090048718f685c6bee6b3d2c25..github/dependabot.yml, one doctoring note, and three executable regression contracts. HistoricalCHANGELOG.mdchurn was removed while reconciling to current protected truth.Atomic v4.37.9 lifecycle
Every checked-in
github/codeql-action/init,autobuild,analyze, andupload-sarifreference now uses immutable commitcdf488f595d80d6e07e03d4674febd5ab45fa938withv4.37.9annotation.Fresh upstream resolution on 2026-09-02 found
refs/tags/v4.37.9-> annotated tag objecta35ac6e6798d72df5475948b28efb89edc2e19ca-> commitcdf488f595d80d6e07e03d4674febd5ab45fa938. The tag is unsigned, so this PR makes no signed-tag claim. v4.37.9 advances the default CodeQL bundle to 2.26.4.services/analysis-engine/tests/test_codeql_action_revision_contract.pyscans every workflow forinit|autobuild|analyze|upload-sarif, deliberately catches mutable/malformed refs, and requires the one exact reviewed SHA plus matching release annotation.codeql.ymladditionally must keep init/autobuild/analyze atomic.Transferred #1026 behavior
The competing lifecycle writer #1026 contained two non-version deltas that were not safe to discard. They are now preserved in this canonical branch:
.github/dependabot.ymlroutes GitHub Actions updates to existingarea: ci-cdplusdependencies; Dependabot had explicitly reported that configured labelgithub-actionsdid not exist.test_dependabot_label_contract.pyprevents regression.develop/main, whilepublish_resultsremains default-branch-only. The PR SARIF lane checks out repository-owned extraction/normalization scripts fromgithub.event.pull_request.base.sha, never from the untrusted PR head, and does not usepull_request_target.test_scorecard_pr_code_scanning_contract.pypins that trust boundary.#1026's narrower CodeQL version/uploader tests are semantically covered by the broader all-workflow revision contract here. Its unique routing and Scorecard behavior are explicitly covered by the two transferred contracts above. Predecessor checks, reviews, approvals, and statuses do not transfer.
TDD sequence
e1ed1ced7ac77b36bab9abb744da39a232ecb154: ordinary-merges current protecteddevelopinto this lane and changes only executable contracts. Those contracts require v4.37.9,area: ci-cd, and PR Scorecard trust-boundary behavior while production config/workflows are still protected-base v4.37.0/old routing. This is deterministic source-order RED; no hosted RED is claimed unless a terminal run on that exact intermediate head exists.823a66200f7a9c846147d3632cc167c1c8f08c65: updates only the owning config/workflows/doctoring required to satisfy those contracts.Exact-head verification
Fresh workflows are materializing against exact head
823a66200f7a9c846147d3632cc167c1c8f08c65. At the latest refetch, required checks includingscorecard,osv-scan,dependency-review, andtrivy-fsare queued, therefore non-passing. All predecessor-head evidence is invalid for this head. There are no current review submissions or inline review threads; an independent non-author exact-head approval is still absent.Split dependency ownership
Fresh v4.37.9 component PRs such as #1135 (
autobuild), #1139 (upload-sarif), and #1141 (analyze) are dependency fragments, not independent lifecycle authority. Do not merge them separately or transfer their checks/reviews. Do not close those split PRs merely because this branch now contains their version delta: close them only after this coordinated lifecycle is accepted under the protected merge gate.#783's JavaScript dependency-security baseline is already in protected
developancestry, so stale text that treats #783 as pending is not a blocker here.Security Notes
The change executes one reviewed immutable CodeQL Action revision across all phases and narrows PR Scorecard script authority to the protected base SHA. It adds no application filesystem, URL, model, database, IPC, credential, or runtime-network authority. Pull-request code-scanning upload capability still depends on GitHub token/repository policy; this PR does not fabricate success for forks or actors without the required permission.
Merge gate
Keep Draft and unmerged until this unchanged exact head has every applicable repository and central CI/security/SAST/SBOM/supply-chain/coverage/release check terminal-success, zero valid unresolved findings, a qualifying independent non-author last-push approval, and ordinary protected-branch acceptance. Queued, pending, skipped-required, cancelled, failed, neutral, stale, predecessor-head, protected-base, self/author, model-only, status-only, or administrative-bypass evidence is non-passing. Never force-push, self-approve, weaken a gate, or merge one CodeQL phase independently.
Relates to #966.