fix(egress): bound anonymous GitHub API authority - #500
Draft
seonghobae wants to merge 550 commits into
Draft
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Aug 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current repair authority
Canonical Noema credential-egress hardening, CI/release-evidence ordering, and exact-head validator-evidence lane. Protected
mainis9fd64b184a7df52922efe0b6c121d714f6f6217d. Current exact head isdf110e815ca20d14919516179a79d8a793e9dd64; the PR is open / Draft / mergeable. Predecessor evidence never transfers across head movement.Current Noema-owned repair — acquisition audit timeout authority
Predecessor exact head
f307d135b77f6f7fa9740be1c058be8bff6f6c31produced a real hosted Application failure in run33280149484/ job99173836643: the forged acquisition-data-room integrity subprocess test timed out at Vitest's 5-second default while the child process itself was intentionally bounded at 30 seconds. The other 3,180 tests passed. This was a Noema-owned test reliability/evidence defect: a slower hosted runner could fail before the test's own bounded subprocess contract had time to complete.An intervening compatible writer advanced the same canonical branch. The current test now gives that integration-style case an explicit 35-second Vitest timeout while preserving the child process's 30-second timeout. The earlier intent was therefore adopted rather than duplicated or raced. Current exact-head Application CI is terminal-success, confirming the repaired test no longer produces the false timeout on the hosted runner.
The branch also retains the existing transport-vs-abort race repair and deterministic post-transport cancellation regression, bounded branch/arm coverage diagnostics, malformed-header fail-closed handling, exact method and
Bearerauthority, reviewed-header raw-byte canonicality, destination/path allowlists, least-privilege installation-token body, repository-installation ownership verification, OIDC discovery/JWKS role separation, redirect refusal, bounded response streaming, deadline/cancellation classification, credential-bearing transport failure policy, and deterministic dependency-license inventory before acquisition-manifest generation.Exact current evidence
Only evidence bound to unchanged exact head
df110e815ca20d14919516179a79d8a793e9dd64is eligible:33280939472: terminal-success;33280939455: terminal-success;33280939457: terminal-success;patch-validator-image33280939454: in progress — non-passing until terminal;Do not infer current image/runtime/SBOM/provenance PASS or merge readiness until
33280939454is terminal on this unchanged head and its checkout/evidence identities are inspected.Read-only dependency boundary
Protected central
.github/mainis6c8ee24046d743b3981c566c6e29f99f09137f6a. Separate consumer owner.github#834remains exact headb3a78a914675892002054eca625000977c012e1aon historical base3a7941aa92de00b8b39fd11cbe7bf3da2fbbeddc, open / Ready but non-mergeable; protected central main is 123 commits ahead of that base. Its existing owner checkpoint was advanced in place with the current Noema head and exact gate identities. Owner action remains non-destructive convergence onto protected central main, fresh exact-head checks/review under central governance, protected integration, then one real Noema OIDC exchange canary proving repository/workflow/expiry/trace binding, mask-before-output token export, and no credential disclosure. No Noema producer workaround narrows the stable{ok,data,trace_id}/data.tokencontract.Merge boundary
Keep Draft. Do not mark Ready or merge until one unchanged exact head has every applicable CI/security/coverage/package/SBOM/provenance/release gate terminal-clean, exact 100% owned-production coverage is proven, live protected base/governance is freshly unchanged, zero valid unresolved findings remain, and the central consumer dependency is authoritative through its own owner followed by a fresh real Noema OIDC canary.