Skip to content

P0: Final security review of governance-plane reusable workflow and reconciliation boundaries #11

Description

@BunsDev

Outcome

Independently review the security-hardening commit on PR #7 before merge, concentrating on the boundaries that could otherwise turn coordination metadata into a confused deputy.

Current hardened head: 3c25c43d30cc7970f3735f103018555e75e09ed6.

Review focus

  • Direct reusable-workflow call-site parsing and equality of uses SHA, literal with.policy_ref, and runtime policy input.
  • Rejection of nested reusable calls, expressions/aliases, mutable refs, and secrets: inherit.
  • Caller workflow path containment beneath .github/workflows/.
  • Target manifest identity binding to the actual calling repository.
  • R3/R4 protected-path and canonical adapter requirements.
  • Evidence and manifest path traversal, symlink, missing-file, and repository-root escape handling.
  • Exact bot-owned drift-issue selection and duplicate ambiguity handling.
  • Read-only token permissions and persist-credentials: false on checkouts.
  • Whether any check relies on caller-controlled data before binding it to trusted context.
  • Whether generated views or registry records could be interpreted as protected OpenCoven authority.

Acceptance criteria

  • Review the exact two-commit PR diff and remote Actions evidence.
  • Confirm all 27 positive/negative tests exercise the intended invariant rather than only implementation detail.
  • Attempt at least one adversarial caller workflow fixture and one path-escape fixture not already in the suite.
  • Confirm no OIDC or additional write permission is needed for the validation path.
  • Confirm the scheduled observer can mutate only its exact managed issue and no administrative setting.
  • Record request-changes findings on PR feat(governance): establish the OpenCoven organization control plane #7 or approve the reviewed boundary.
  • Do not merge as part of this issue.

This review is evidence for repository governance only. It cannot authorize familiar identity, Threads, Psyche, Coven, release, publication, or organization-administration operations.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions