fix(egress): bound anonymous GitHub API authority - #500
Merged
Conversation
|
Warning Review limit reachedNext included review available in 42 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (35)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Aug 23, 2026
seonghobae
marked this pull request as ready for review
August 30, 2026 09:56
seonghobae
added a commit
that referenced
this pull request
Aug 30, 2026
seonghobae
pushed a commit
that referenced
this pull request
Aug 30, 2026
…-registry-stream-bounds Co-Authored-By: Claude <noreply@anthropic.com>
seonghobae
pushed a commit
that referenced
this pull request
Aug 30, 2026
…-registry-capability-path-authority Co-Authored-By: Claude <noreply@anthropic.com>
seonghobae
pushed a commit
that referenced
this pull request
Aug 30, 2026
…ion-data-room-canonical-authority Co-Authored-By: Claude <noreply@anthropic.com>
seonghobae
pushed a commit
that referenced
this pull request
Aug 30, 2026
…on-evidence-public-endpoint Co-Authored-By: Claude <noreply@anthropic.com> # Conflicts: # test/acquisition-data-room-integrity.test.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current repair authority
Canonical Noema credential-egress hardening, CI/release-evidence ordering, and exact-head patch-validator image evidence lane. Protected
mainis GitHub-verified9fd64b184a7df52922efe0b6c121d714f6f6217d. Current exact head isd51ef8ac0cf87fda183c7680c2f2b017e496d10b; fresh comparison isaheadwith merge base equal to protected main (behind=0). The PR is open / Draft / mergeable. Predecessor evidence never transfers across head movement.Noema-owned repairs
Exact current evidence
Only unchanged exact-head evidence for
d51ef8ac0cf87fda183c7680c2f2b017e496d10bis eligible.33292648472/ job99206868880: terminal-success, including exact checkout, live-base/lockfile control, typecheck, release tests/security/KPI, fresh dependency-license inventory, acquisition manifest/integrity and final base-drift refusal.33292648501/ job99206868824: terminal-success, including hash-pinned dependencies, exact 100% line+branch coverage, 100% docstring coverage, authenticated/scanned distroless sandbox and real no-network CodeGraph smoke.33292648492: terminal-success on the exact head under current protected central scanner authority.patch-validator-image33292648524/ job99206918709: terminal-success. Every step through exact checkout/stale-head refusal, scanner acquisition, exact dependency materialization, image build, static Node identity, metadata exclusion, real no-network/read-only/non-root smoke, CycloneDX SBOM, binary/runtime/embedded dependency vulnerability receipts, exact-source/image receipt verification, post-verification stale-head refusal and bounded artifact upload completed successfully.patch-validator-image-verification-d51ef8ac0cf87fda183c7680c2f2b017e496d10bis bound to this exact source revision and has archive digestsha256:b442cc9c7fcddb5723d83e746f02177a67cf248093e8afaad53f8981f654ef59.image-verification.jsonreportsstatus=passed, image digestsha256:8cae0ebc32de0492504a1c38fe4c50b4a895749ea508ec239a9f7a181dba13f2, CycloneDX 1.7, 69 components, 0 image vulnerabilities, 0 binary vulnerability matches and 0 blocked embedded-runtime vulnerabilities. Four embedded-runtime scanner matches are explicitly reviewed non-applicable (one nghttp2 proxy-only CVE and three legacy V8 CVEs); none is promoted as a clean result without applicability evidence.smoke-result.jsonreportsstatus=passedfor the same source revision/image digest; image metadata fixes runtime user at65532:65532.Live governance
Repository-effective organization ruleset
18794436is active on~DEFAULT_BRANCH, requires central.github/workflows/security-scan.yml@refs/heads/main, hasbypass_actors=[], and reportscurrent_user_can_bypass=never. Protected central scanner authority is GitHub-verified.github/main@6c8ee24046d743b3981c566c6e29f99f09137f6a; the protected Security Scan has no PR-base filter, verifies explicit base/head authority, and treats unavailable dependency-comparison evidence as failure rather than clean.Code-owner approval is intentionally disabled for this single-maintainer repository; current live governance does not require an independent approval for this PR.
Read-only consumer lane
Central
.github#834remains the separate owner of the central review workflow's stabledata.tokenconsumer validation. It is currently exact headb3a78a914675892002054eca625000977c012e1a, diverged from protected central main and non-mergeable. Noema does not mutate that repository's source/refs/workflows/PR source state or weaken its producer contract as a workaround.That consumer repair is not a causal prerequisite for merging this Noema-local egress/image hardening: this PR does not change the stable
{ok,data,trace_id}success-envelope schema consumed by #834. Owner-dependency latency therefore remains isolated to the real central consumer/canary lane. After central integration, the separate acceptance criterion remains one real OIDC exchange proving repository/workflow/expiry/trace binding, visible-ASCII credential handling, mask-before-output export and no credential disclosure.Merge boundary
Noema-local merge evidence is terminal-clean on one unchanged exact head and unchanged protected base, with zero valid unresolved findings and exact 100% owned-production coverage. The remaining repository-state transition is to leave Draft and merge the unchanged exact head through normal GitHub governance; do not force-push, bypass the ruleset, self-approve, or transfer evidence after any head/base movement.