Skip to content

build(deps): align CodeQL 4.37.6 on accepted security base - #107

Closed
seonghobae wants to merge 1 commit into
fix/atheris-interpreter-lockfrom
build/codeql-4.37.6-on-security-base
Closed

build(deps): align CodeQL 4.37.6 on accepted security base#107
seonghobae wants to merge 1 commit into
fix/atheris-interpreter-lockfrom
build/codeql-4.37.6-on-security-base

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Purpose

Rebuild the CodeQL 4.37.6 dependency update on the exact current security base instead of carrying the historical protected-main Semgrep findings that block PR #106.

Exact identity

  • Base branch: fix/atheris-interpreter-lock (PR fix(security): pin provider egress and repair the Atheris lock #96)
  • Base exact head at reconstruction: 3703d0da9823b8258a0be94f1801aa5d61bfad9f
  • Contributor head: 28088b9fc86d975b43637b7758d25e20d61c5786
  • Changed file: .github/workflows/security.yml only
  • Change: update both github/codeql-action/init and github/codeql-action/analyze atomically from v4.37.0 to immutable v4.37.6 commit 5595ccaf912efad79be6eef63a5619ff05969be3

RCA and replacement rationale

PR #106 targets protected main@6841b71935e0b7cb98fb52bcb4709cc5100c8d87. Its current SAST run checks out synthetic merge af0bfebc046b9b6a4832562c929224ad2c429eba and fails on the five inherited protected-main findings in cost_ledger.py and orchestrator.py; its one-file CodeQL action diff does not touch those findings. PR #96 repairs that shared security boundary. Suppressing findings or duplicating the security repair in a dependency-only PR would be the wrong root-cause remedy.

This replacement therefore applies the same atomic CodeQL update directly over the accepted exact #96 head. It must remain Draft while #96 is Draft or unintegrated. If #96 moves, this head/base evidence becomes historical and must be reconciled before acceptance.

Current exact-head evidence

All repository-local workflows explicitly fetched and checked out contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 with checkout credentials disabled:

  • Tests run 31353149983, job 93347600723: success with 566 passed, 100% production statement and branch coverage (3,667 statements / 934 branches, zero misses/partials), and 100% public-docstring coverage.
  • Security run 31353149993: success. Python supply-chain job 93347600805 found no known vulnerabilities and published CycloneDX SBOM artifact 9049659096; CodeQL job 93347600840 analyzed 85/85 Python files and 3/3 workflow files using the updated immutable CodeQL 4.37.6 pin.
  • Fuzz run 31353149986: success. Hypothesis job 93347601110 completed 8 property tests; Atheris job 93347601160 completed all four bounded targets without a crash artifact.
  • CodeRabbit commit status: success, classified as status-only evidence rather than a formal review or approval.
  • Formal reviews: zero. Unresolved inline review threads: zero. Qualifying independent non-author approval: absent.

This evidence proves only repository-local exact-head Tests, Security, Fuzz, coverage, docstrings, dependency audit, SBOM generation, and CodeQL execution. PR #96 remains Draft and unintegrated, so this PR remains Draft. No result here substitutes for protected-base integration, fresh required automated review, or qualifying independent approval.

Acceptance

Require fresh exact-head repository checks and current review evidence for this reconstructed head. Do not promote predecessor, stale-base, synthetic-merge-only, status-only, author-only, queued, skipped-required, absent, failed, or rate-limited evidence to success. Merge only after #96 reaches protected integration, this bounded update is reconciled onto that exact result if needed, all required checks/security gates pass, zero valid unresolved findings remain, and a qualifying independent non-author approval applies to the unchanged head.

Supersedes #106 after replacement identity and checks are confirmed.

Summary by CodeRabbit

  • 개선 사항
    • 보안 분석 도구를 최신 버전으로 업데이트하여 보안 검사 안정성을 향상했습니다.

Current-head automated review refresh (2026-08-12)

CodeRabbit full-review comment 5263499272 inspected exact contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 against exact stacked base 3703d0da9823b8258a0be94f1801aa5d61bfad9f and found no current-head actionable finding. It independently verified the one-file range, atomic init/analyze update, immutable 5595ccaf912efad79be6eef63a5619ff05969be3 pin, annotated v4.37.6 tag resolution, valid commit signature, and unchanged permissions/supply-chain behavior. This is automated comment evidence, not a formal review or qualifying independent human approval. Formal reviews and unresolved threads remain zero; keep this PR Draft behind unintegrated #96.

@coderabbitai

coderabbitai Bot commented Aug 10, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4cd13f2d-f86f-457e-8d5b-2a717abbf2a6

📥 Commits

Reviewing files that changed from the base of the PR and between 3703d0d and 28088b9.

📒 Files selected for processing (1)
  • .github/workflows/security.yml

📝 Walkthrough

Walkthrough

CodeQL initanalyze 액션의 버전을 v4.37.0에서 v4.37.6으로 업데이트했습니다. Python 분석 설정과 분석 카테고리는 유지했습니다.

Changes

CodeQL 워크플로 업데이트

Layer / File(s) Summary
CodeQL 액션 버전 고정 업데이트
.github/workflows/security.yml
CodeQL initanalyze 액션을 v4.37.6으로 업데이트했습니다. Python 언어, none 빌드 모드, 분석 카테고리는 유지했습니다.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related issues

  • ContextualWisdomLab/semantic-data-portal#53: CodeQL 액션 버전 업데이트와 Analyze (actions) 체크 설정을 다루므로 관련될 수 있습니다.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 CodeQL 의존성 버전 4.37.6 정렬이라는 주요 변경 사항을 명확하게 설명합니다.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch build/codeql-4.37.6-on-security-base

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Review exact contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 against exact live base 3703d0da9823b8258a0be94f1801aa5d61bfad9f. The diff is limited to atomically updating both github/codeql-action/init and analyze from immutable v4.37.0 to immutable v4.37.6. Exact-head Tests 31353149983, Security 31353149993, and Fuzz 31353149986 are complete and successful. Report only current-head actionable findings; status-only, predecessor, stale-base, author-only, and synthetic-merge evidence do not qualify as review or approval.

@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown

@seonghobae I will review the requested exact head against the specified base. I will report only actionable findings on the current head.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review

Review exact unchanged contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 against exact parent head 3703d0da9823b8258a0be94f1801aa5d61bfad9f. The one-file diff must atomically retain immutable github/codeql-action/init and analyze pins while moving both from v4.37.0 to v4.37.6. Exact-head Tests 31353149983, Security 31353149993, and Fuzz 31353149986 are complete and successful; unresolved inline threads are zero. Treat predecessor-head, status-only, author-only, synthetic-merge, and the current CodeRabbit rate-limit response as non-review evidence. Verify the two pins match, the immutable commit is valid for the declared release, workflow permissions and analysis semantics are unchanged, and no dependency/provenance boundary regresses. Submit only a current-head formal review; automated evidence does not substitute for qualifying independent human approval.

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

Please review exact current contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 against exact live base 3703d0da9823b8258a0be94f1801aa5d61bfad9f. Treat predecessor-head evidence as historical and report only current-head actionable findings.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

@seonghobae I will review contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 against base head 3703d0da9823b8258a0be94f1801aa5d61bfad9f. I will report only actionable findings on the current head.

⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 56 minutes.

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review
@opencode-agent
@cwl-noema-review

Review exact contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 against exact stacked base 3703d0da9823b8258a0be94f1801aa5d61bfad9f. The diff is limited to the atomic immutable CodeQL 4.37.6 pin in .github/workflows/security.yml. Treat predecessor, status-only, author-only, synthetic-merge, and model results as non-transferable; report only current-head actionable findings. This Draft remains blocked behind PR #96, and automated/model review is not qualifying independent human approval.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="3703d0da9823b8258a0be94f1801aa5d61bfad9f"
head="28088b9fc86d975b43637b7758d25e20d61c5786"

echo "== Exact commit availability and relationship =="
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head"
printf 'base: '; git rev-parse "$base"
printf 'head: '; git rev-parse "$head"
printf 'merge-base: '; git merge-base "$base" "$head"

echo "== Changed files and diff =="
git diff --name-status "$base" "$head"
git diff --check "$base" "$head"
git diff --no-ext-diff --unified=80 "$base" "$head" -- .github/workflows/security.yml

echo "== Workflow outline and relevant content at head =="
ast-grep outline .github/workflows/security.yml --items all || true
nl -ba .github/workflows/security.yml | sed -n '1,320p'

echo "== CodeQL pin occurrences at base and head =="
for ref in "$base" "$head"; do
  echo "-- $ref --"
  git show "${ref}:.github/workflows/security.yml" |
    rg -n -C 3 'github/codeql-action/(init|analyze)@|permissions:|security-events:|actions: read|contents: read|category:|languages:|build-mode:'
done

echo "== PR metadata and upstream action commit metadata =="
gh pr view 107 --repo ContextualWisdomLab/contextual-orchestrator \
  --json number,state,isDraft,baseRefOid,headRefOid,changedFiles,files,url
gh api repos/github/codeql-action/commits/5595ccaf912efad79be6eef63a5619ff05969be3 \
  --jq '{sha:.sha,message:.commit.message,verification:.commit.verification,html_url:.html_url}'
gh api repos/github/codeql-action/git/ref/tags/v4.37.6 \
  --jq '{ref:.ref,object_type:.object.type,object_sha:.object.sha}'

Length of output: 5736


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="3703d0da9823b8258a0be94f1801aa5d61bfad9f"
head="28088b9fc86d975b43637b7758d25e20d61c5786"
pin="5595ccaf912efad79be6eef63a5619ff05969be3"

echo "== Full workflow at the exact head =="
git show "${head}:.github/workflows/security.yml" | sed -n '1,220p'

echo "== Semantic diff excluding CodeQL action references =="
git diff --no-ext-diff --unified=8 "$base" "$head" -- .github/workflows/security.yml |
  grep -vE '^[+-].*github/codeql-action/(init|analyze)@|^[-+]{3}|^@@' || true

echo "== Action pins in base and head =="
for ref in "$base" "$head"; do
  printf '%s: ' "$ref"
  git show "${ref}:.github/workflows/security.yml" |
    grep -E '^[[:space:]]*uses: github/codeql-action/(init|analyze)@' || true
done

echo "== PR `#107` exact metadata =="
gh pr view 107 --repo ContextualWisdomLab/contextual-orchestrator \
  --json number,state,isDraft,baseRefName,baseRefOid,headRefName,headRefOid,changedFiles,url

echo "== CodeQL v4.37.6 tag and requested commit =="
gh api repos/github/codeql-action/git/ref/tags/v4.37.6
gh api repos/github/codeql-action/commits/"$pin" \
  --jq '{sha:.sha,html_url:.html_url,message:.commit.message,verification:.commit.verification}'

echo "== Resolve annotated tag target when applicable =="
tag_object="$(gh api repos/github/codeql-action/git/ref/tags/v4.37.6 --jq '.object.type + " " + .object.sha')"
printf '%s\n' "$tag_object"
if [ "${tag_object%% *}" = "tag" ]; then
  gh api "repos/github/codeql-action/git/tags/${tag_object#* }" \
    --jq '{tag:.tag,object_type:.object.type,object_sha:.object.sha,verification:.verification}'
fi

Length of output: 8695


@seonghobae Full review complete for contributor head 28088b9fc86d975b43637b7758d25e20d61c5786 against base 3703d0da9823b8258a0be94f1801aa5d61bfad9f.

I found no current-head actionable findings.

Verified items:

  • The base commit is an ancestor of the contributor head.
  • PR #107 is Draft and has the requested base and head commits.
  • The exact range changes only .github/workflows/security.yml.
  • Both github/codeql-action/init and github/codeql-action/analyze update atomically.
  • Both actions use the same immutable SHA: 5595ccaf912efad79be6eef63a5619ff05969be3.
  • GitHub’s annotated v4.37.6 tag resolves to that SHA.
  • GitHub reports a valid signature for the pinned commit.
  • Workflow permissions, checkout behavior, CodeQL configuration, and Python supply-chain steps are unchanged.

This review does not qualify as independent human approval. PR #107 must remain blocked until PR #96 reaches protected integration and the required current-head evidence and independent approval are present.

✅ Action performed

Full review finished.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Closed by autonomous commercial loop: draft dependency/tooling PR with CHANGES_REQUESTED or stack base risk. Prefer Dependabot re-open against current main after #111#114 land, rather than carrying long-lived draft dep branches. (build(deps): align CodeQL 4.37.6 on accepted security base)

@seonghobae seonghobae closed this Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant