-
Notifications
You must be signed in to change notification settings - Fork 731
feat(project-profiling): vuln reporting protocol [CM-1331] #4413
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
mbani01
wants to merge
12
commits into
main
Choose a base branch
from
feat/vuln-reporting-protocol
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
12 commits
Select commit
Hold shift + click to select a range
366de3c
feat: add reporting protocol tables
mbani01 4dd407d
feat: add deterministic security policy classifier
mbani01 4f0a789
feat: add parsed protocol validator
mbani01 826a217
feat: add blob and linked-page fetchers for reporting protocol
mbani01 e4f7157
feat: add bedrock LLM protocol extraction with strict schema
mbani01 0474d82
feat: add reporting protocol parse stage
mbani01 51f9e23
feat: add reporting protocol assemble stage
mbani01 2232188
feat: wire reporting protocol workflow and schedule
mbani01 bfef882
docs: record reporting protocol decisions in ADR-0010
mbani01 424a10e
fix(review): address PR #4413 review feedback
mbani01 be30d28
fix(review): address review feedback
mbani01 a492849
Merge branch 'main' into feat/vuln-reporting-protocol
mbani01 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
26 changes: 26 additions & 0 deletions
26
backend/src/osspckgs/migrations/V1785283200__reporting_protocol.sql
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,26 @@ | ||
| -- Content-keyed parse cache for declared security policies (files + linked pages), | ||
| -- and the assembled per-repo reporting protocol. See ADR-0010 addendum. | ||
| CREATE TABLE IF NOT EXISTS security_policy_parses ( | ||
| blob_oid TEXT PRIMARY KEY, -- git blob oid for files; sha256 of extracted text for linked pages | ||
| source_kind TEXT NOT NULL, -- 'security-file' | 'linked-page' | ||
| url TEXT, -- linked-page rows only: the fetched URL (join key from linked_urls) | ||
| parser TEXT NOT NULL, -- 'deterministic' | 'llm' | ||
| parser_version INT NOT NULL, | ||
| status TEXT NOT NULL, -- 'ok' | 'template' | 'degraded' | ||
| parsed JSONB NOT NULL DEFAULT '{}', | ||
| linked_urls TEXT[] NOT NULL DEFAULT '{}', | ||
| parsed_at TIMESTAMPTZ NOT NULL DEFAULT NOW() | ||
| ); | ||
|
|
||
| CREATE INDEX IF NOT EXISTS security_policy_parses_linked_page_url_idx | ||
| ON security_policy_parses (url) | ||
| WHERE source_kind = 'linked-page'; | ||
|
|
||
| CREATE TABLE IF NOT EXISTS repo_reporting_protocols ( | ||
| repo_id BIGINT PRIMARY KEY REFERENCES repos(id) ON DELETE CASCADE, | ||
| declared BOOLEAN NOT NULL, | ||
| methods JSONB NOT NULL DEFAULT '[]', | ||
| guidelines JSONB, | ||
| sources JSONB NOT NULL DEFAULT '[]', | ||
| assembled_at TIMESTAMPTZ NOT NULL DEFAULT NOW() | ||
| ); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
2 changes: 2 additions & 0 deletions
2
services/apps/packages_worker/src/bin/security-contacts-worker.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,8 +1,10 @@ | ||
| import { scheduleReportingProtocolIngestion } from '../security-contacts/protocol/schedule' | ||
| import { scheduleSecurityContactsIngestion } from '../security-contacts/schedule' | ||
| import { svc } from '../service' | ||
|
|
||
| setImmediate(async () => { | ||
| await svc.init() | ||
| await scheduleSecurityContactsIngestion() | ||
| await scheduleReportingProtocolIngestion() | ||
| await svc.start() | ||
| }) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.