Skip to content

fix(oidc): reject non-canonical workflow source configuration - #500

Draft
seonghobae wants to merge 404 commits into
mainfrom
fix/oidc-workflow-sha-canonical-config
Draft

fix(oidc): reject non-canonical workflow source configuration#500
seonghobae wants to merge 404 commits into
mainfrom
fix/oidc-workflow-sha-canonical-config

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Current repair authority

This PR is the earliest open Noema dependency root. Protected Noema main remains GitHub-verified 2c83355529447248c246805d1954f268e027d2ab. Current exact head is fba53f19217471e1d361e0d30f8092435fcf14df, an exact descendant of protected main. Keep Draft.

The branch's cumulative history contains the test-first OIDC/workflow-source, replay, GitHub App, response-integrity, egress, distributed-rate-limit, readiness, reviewer-sandbox and patch-validator work already reviewed on this stack. Git history and exact-head tests remain the detailed evidence authority; this body records the current merge boundary rather than treating predecessor runs as transferable.

Current repair — roll audited central workflow trust to protected current source

Protected central .github/main advanced from e5e0d3652a19d12db29e687924dbaf978cd78912 to GitHub-verified e1b03eebc6dc5c85aed393e5928927c96376cf46 through independently owned central PR #1379. Fresh blob reads prove .github/workflows/noema-review.yml is unchanged across those two protected central revisions at blob 5c60782adb8be11d6538caea269a4bdfab7ab4d1. GitHub OIDC job_workflow_sha nevertheless binds the caller to repository commit identity, so retaining the older e5e0d... allowlist would reject the current protected central caller.

Test-first 7cbfcaa8953f6c40ed94c922e1587e7a570bd1fe changes test/trusted-workflow-source-rollforward.test.ts to require e1b03eeb... while production wrangler.toml still held e5e0d.... Its CI/reviewer/Security/image runs were concurrency-cancelled by the immediate production successor, so it is source-level/test-first RED evidence, not claimed terminal hosted RED.

Production 1bed96014a1fb75207fe2b54fbfe56e3967f5f38 changes only wrangler.toml ALLOWED_WORKFLOW_SHA to the audited current protected central SHA. Exact workflow-ref matching, lowercase 40-hex source identity, cryptographic claim verification, repository/workflow binding, replay-before-mint, rate limits, GitHub App scope and fail-closed egress remain unchanged.

Documentation successor/current exact head fba53f19217471e1d361e0d30f8092435fcf14df makes the canonical architecture graph code-current and records the unchanged noema-review.yml blob identity while keeping repository-commit trust explicit.

Exact current evidence

On unchanged exact head fba53f19217471e1d361e0d30f8092435fcf14df:

  • Application CI 33185941265: terminal-success.
  • reviewer-ci 33185941536: terminal-success; exact checkout, hash-pinned dependency install, 100% line+branch coverage, 100% docstring gate, authenticated/scanned sandbox image and real no-network CodeGraph smoke passed.
  • Security Scan 33185941300: workflow-level terminal-success, but not merge-authoritative while the protected-central scanner authority defect remains on protected truth.
  • dedicated patch-validator-image 33185941429: in progress / non-passing at this checkpoint. Predecessor image/SBOM/provenance evidence does not transfer.
  • Formal review remains COMMENTED only. The sole known inline finding is resolved/outdated; zero valid unresolved inline findings are currently known.

Read-only dependency boundary

Protected central .github/main is e1b03eebc6dc5c85aed393e5928927c96376cf46. Its protected security-scan.yml explicitly materializes OSV base/head, but Dependency Review and Trivy still use generic checkout and the dependency-comparison support probe still maps transport/403/404 absence into a non-hard-gated path. Current downstream Security green therefore remains non-authoritative for exact submitted-head proof.

Existing central scanner owner PR #897 is open / Ready / mergeable at actual exact head 74eb5d1753cba1a48e47e9bc05940373181d7b23, aligned to the current protected central base. Fresh source inspection of that exact owner head proves explicit PR-head checkout plus runtime SHA attestation for Dependency Review and Trivy, exact base/head comparison inputs, and fail-closed non-200/transport behavior. Observed exact-head security/SBOM/SAST/OSV/CodeQL/Scorecard workflows are terminal-success, but a qualifying current-head formal APPROVE has not been established. Existing .github#1222 checkpoint comment 5440526640 carries the current owner and Noema canary identities. No foreign central source/ref/workflow/PR-source state was mutated.

Existing central #834 separately owns the protected consumer correction from nonexistent top-level .token to stable data.token; it remains exact head 1a202f9745e90280e3b1bbdead4f78320ba413fc on a historical base and is non-mergeable. Noema does not reshape its stable success envelope as a workaround.

Merge boundary

Do not merge or mark Ready until the unchanged exact head has every applicable CI/security/coverage/package/SBOM/provenance/release gate terminal-clean, dedicated image verification is terminal-clean, protected-central scanner/consumer repairs are authoritative with fresh eligible downstream evidence, live base/governance is freshly unchanged, and zero valid unresolved findings remain.

@coderabbitai

coderabbitai Bot commented Aug 23, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant