fix(oidc): reject non-canonical workflow source configuration - #500
Draft
seonghobae wants to merge 404 commits into
Draft
fix(oidc): reject non-canonical workflow source configuration#500seonghobae wants to merge 404 commits into
seonghobae wants to merge 404 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Aug 23, 2026
16 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current repair authority
This PR is the earliest open Noema dependency root. Protected Noema
mainremains GitHub-verified2c83355529447248c246805d1954f268e027d2ab. Current exact head isfba53f19217471e1d361e0d30f8092435fcf14df, an exact descendant of protected main. Keep Draft.The branch's cumulative history contains the test-first OIDC/workflow-source, replay, GitHub App, response-integrity, egress, distributed-rate-limit, readiness, reviewer-sandbox and patch-validator work already reviewed on this stack. Git history and exact-head tests remain the detailed evidence authority; this body records the current merge boundary rather than treating predecessor runs as transferable.
Current repair — roll audited central workflow trust to protected current source
Protected central
.github/mainadvanced frome5e0d3652a19d12db29e687924dbaf978cd78912to GitHub-verifiede1b03eebc6dc5c85aed393e5928927c96376cf46through independently owned central PR #1379. Fresh blob reads prove.github/workflows/noema-review.ymlis unchanged across those two protected central revisions at blob5c60782adb8be11d6538caea269a4bdfab7ab4d1. GitHub OIDCjob_workflow_shanevertheless binds the caller to repository commit identity, so retaining the oldere5e0d...allowlist would reject the current protected central caller.Test-first
7cbfcaa8953f6c40ed94c922e1587e7a570bd1fechangestest/trusted-workflow-source-rollforward.test.tsto requiree1b03eeb...while productionwrangler.tomlstill helde5e0d.... Its CI/reviewer/Security/image runs were concurrency-cancelled by the immediate production successor, so it is source-level/test-first RED evidence, not claimed terminal hosted RED.Production
1bed96014a1fb75207fe2b54fbfe56e3967f5f38changes onlywrangler.tomlALLOWED_WORKFLOW_SHAto the audited current protected central SHA. Exact workflow-ref matching, lowercase 40-hex source identity, cryptographic claim verification, repository/workflow binding, replay-before-mint, rate limits, GitHub App scope and fail-closed egress remain unchanged.Documentation successor/current exact head
fba53f19217471e1d361e0d30f8092435fcf14dfmakes the canonical architecture graph code-current and records the unchangednoema-review.ymlblob identity while keeping repository-commit trust explicit.Exact current evidence
On unchanged exact head
fba53f19217471e1d361e0d30f8092435fcf14df:33185941265: terminal-success.33185941536: terminal-success; exact checkout, hash-pinned dependency install, 100% line+branch coverage, 100% docstring gate, authenticated/scanned sandbox image and real no-network CodeGraph smoke passed.33185941300: workflow-level terminal-success, but not merge-authoritative while the protected-central scanner authority defect remains on protected truth.patch-validator-image33185941429: in progress / non-passing at this checkpoint. Predecessor image/SBOM/provenance evidence does not transfer.Read-only dependency boundary
Protected central
.github/mainise1b03eebc6dc5c85aed393e5928927c96376cf46. Its protectedsecurity-scan.ymlexplicitly materializes OSV base/head, but Dependency Review and Trivy still use generic checkout and the dependency-comparison support probe still maps transport/403/404 absence into a non-hard-gated path. Current downstream Security green therefore remains non-authoritative for exact submitted-head proof.Existing central scanner owner PR #897 is open / Ready / mergeable at actual exact head
74eb5d1753cba1a48e47e9bc05940373181d7b23, aligned to the current protected central base. Fresh source inspection of that exact owner head proves explicit PR-head checkout plus runtime SHA attestation for Dependency Review and Trivy, exact base/head comparison inputs, and fail-closed non-200/transport behavior. Observed exact-head security/SBOM/SAST/OSV/CodeQL/Scorecard workflows are terminal-success, but a qualifying current-head formal APPROVE has not been established. Existing.github#1222checkpoint comment5440526640carries the current owner and Noema canary identities. No foreign central source/ref/workflow/PR-source state was mutated.Existing central #834 separately owns the protected consumer correction from nonexistent top-level
.tokento stabledata.token; it remains exact head1a202f9745e90280e3b1bbdead4f78320ba413fcon a historical base and is non-mergeable. Noema does not reshape its stable success envelope as a workaround.Merge boundary
Do not merge or mark Ready until the unchanged exact head has every applicable CI/security/coverage/package/SBOM/provenance/release gate terminal-clean, dedicated image verification is terminal-clean, protected-central scanner/consumer repairs are authoritative with fresh eligible downstream evidence, live base/governance is freshly unchanged, and zero valid unresolved findings remain.