fix(kpi): reject compact credential-shaped source IDs - #496
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current-base exact merge-result promotion is now active as #507 at |
Summary
Prevent KPI provenance
sourceIdfrom accepting credential-shaped, locator-shaped, executable-scheme, percent-encoded, or display-ambiguous labels that can leak secret material or create non-canonical retained buyer evidence.Root cause and repair lineage
The shared
hasUnsafeSourceIdboundary rejects credential-shaped labels, control/format/separator characters, surrounding whitespace, Unicode normalization ambiguity, hierarchical/non-hierarchical executable locators, query-bearing authority and percent-encoded identity material. Existing credential/control/space/NFKC/password-alias hardening remains intact.Scope / evidence boundary
This hardens provenance-label validation only. It does not synthesize production KPI evidence and does not satisfy issue #3's >=30-day authenticated production-data requirement. Technical gate success is not production, deployment, legal, or acquisition evidence.
Current exact identity and evidence
4e2cadbb56cff3b143d70dc99a78b7f7347a8afe;main:2c83355529447248c246805d1954f268e027d2ab;270b66e592330c4f1c7d3b726779b1a6c599c70c;32667243953: terminal-success;32667243783: terminal-success;patch-validator-image32667243882: terminal-success;32667243829: workflow-level terminal-success but not merge-authoritative while protected-central scanner authority remains defective;These results belong to this diverged exact head and must be regenerated after non-destructive convergence; they do not authorize merging the stale-base lane.
Dependency / owner boundary
Earlier Noema dependency root #500 is current exact head
91e72951c739a40d17f8474fd43318837b30c5b2, Draft/mergeable and an exact descendant of protected main. Application33231140202, reviewer33231140178, and workflow-level Security33231140205are terminal-success; dedicated image33231140223remains pending/non-passing. This KPI lane must not overtake it.Protected central
.github/mainis GitHub-verifiede1b03eebc6dc5c85aed393e5928927c96376cf46. Protectedsecurity-scan.ymlstill has generic Dependency Review/Trivy checkout and a Dependency Review support probe that can map exact-comparison HTTP 403/404 tosupported=falseplus successful completion. Downstream Security success cannot be promoted to submitted-head-authoritative evidence.Canonical central scanner owner #897 remains open / Ready / mergeable at exact head
74eb5d1753cba1a48e47e9bc05940373181d7b23on the current protected central base, but required Strix provider-unavailable evidence, exact-current OpenCodeCHANGES_REQUESTED, and absence of a qualifying independent approval remain non-passing. Central #834 separately owns the protected Noema stable exchange-envelope consumer correction from nonexistent top-level.tokentodata.tokenand remains exact head1a202f9745e90280e3b1bbdead4f78320ba413fcon a historical non-mergeable base. No Noema producer workaround belongs here.Merge boundary
Keep Draft. After #500 integrates or protected main otherwise moves, refetch this exact lane; if no writer conflict exists, converge non-destructively onto the then-current protected main and regenerate every applicable exact-head CI/security/coverage/package/SBOM/provenance gate. Do not reuse current Security success after convergence. No outbound license or production KPI claim is made here.