From 40bc6d25448f324dfc4fb99b74fe0061d46af0b5 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 17 Dec 2025 23:30:27 +0000 Subject: [PATCH] fix(security): correct HTTP detection and SHA-pin actions - Fix critical bug in security-policy.yml: was searching for https:// instead of http:// for insecure URL detection - SHA-pin all actions in scorecard.yml for supply chain security - Update ci.yml RSR check to accept README.adoc and LICENSE.txt - Update justfile validate-rsr to match actual file names - Update STATE.scm with security hardening session --- .github/workflows/ci.yml | 4 ++-- .github/workflows/scorecard.yml | 10 ++++---- .github/workflows/security-policy.yml | 8 +++---- STATE.scm | 33 ++++++++++++++++++++------- justfile | 4 ++-- 5 files changed, 38 insertions(+), 21 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f43083b..adb122e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -177,8 +177,8 @@ jobs: - name: Check Documentation run: | echo "Checking required files..." - test -f README.md || (echo "❌ README.md missing" && exit 1) - test -f LICENSE || (echo "❌ LICENSE missing" && exit 1) + test -f README.adoc || test -f README.md || (echo "❌ README missing" && exit 1) + test -f LICENSE.txt || test -f LICENSE || (echo "❌ LICENSE missing" && exit 1) test -f SECURITY.md || (echo "❌ SECURITY.md missing" && exit 1) test -f CODE_OF_CONDUCT.md || (echo "❌ CODE_OF_CONDUCT.md missing" && exit 1) test -f CONTRIBUTING.md || (echo "❌ CONTRIBUTING.md missing" && exit 1) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index a073b17..8219b6d 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -14,17 +14,17 @@ jobs: security-events: write id-token: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 with: persist-credentials: false - + - name: Run Scorecard - uses: ossf/scorecard-action@v2.3.1 + uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0 with: results_file: results.sarif results_format: sarif - + - name: Upload results - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@662472033e021d55d94146f66f6058822b0b39fd # v3.28.1 with: sarif_file: results.sarif diff --git a/.github/workflows/security-policy.yml b/.github/workflows/security-policy.yml index 90c2378..a1753f9 100644 --- a/.github/workflows/security-policy.yml +++ b/.github/workflows/security-policy.yml @@ -4,20 +4,20 @@ jobs: check: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 - name: Security checks run: | FAILED=false - + # Block MD5/SHA1 for security (allow for checksums/caching) WEAK_CRYPTO=$(grep -rE 'md5\(|sha1\(' --include="*.py" --include="*.rb" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" . 2>/dev/null | grep -v 'checksum\|cache\|test\|spec' | head -5 || true) if [ -n "$WEAK_CRYPTO" ]; then echo "⚠️ Weak crypto (MD5/SHA1) detected. Use SHA256+ for security:" echo "$WEAK_CRYPTO" fi - + # Block HTTP URLs (except localhost) - HTTP_URLS=$(grep -rE 'https://[^l][^o][^c]' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.yaml" --include="*.yml" . 2>/dev/null | grep -v 'localhost\|127.0.0.1\|example\|test\|spec' | head -5 || true) + HTTP_URLS=$(grep -rE 'http://[^l][^o][^c]' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.yaml" --include="*.yml" . 2>/dev/null | grep -v 'localhost\|127.0.0.1\|example\|test\|spec' | head -5 || true) if [ -n "$HTTP_URLS" ]; then echo "⚠️ HTTP URLs found. Use HTTPS:" echo "$HTTP_URLS" diff --git a/STATE.scm b/STATE.scm index 9097e52..08d38ef 100644 --- a/STATE.scm +++ b/STATE.scm @@ -15,7 +15,7 @@ '((version . "0.1.0") (schema-version . "1.0") (created . "2025-12-15") - (updated . "2025-12-15") + (updated . "2025-12-17") (project . "double-track-browser") (repo . "github.com/hyperpolymath/double-track-browser"))) @@ -41,7 +41,7 @@ (define current-position '((phase . "v0.1 - Initial Setup and RSR Compliance") - (overall-completion . 25) + (overall-completion . 30) (components ((rsr-compliance @@ -49,10 +49,15 @@ (completion . 100) (notes . "SHA-pinned actions, SPDX headers, multi-platform CI"))) + (security + ((status . "hardened") + (completion . 85) + (notes . "Fixed HTTP/HTTPS detection bug, SHA-pinned scorecard workflow, updated RSR validation for README.adoc/LICENSE.txt"))) + (documentation ((status . "foundation") - (completion . 30) - (notes . "README exists, META/ECOSYSTEM/STATE.scm added"))) + (completion . 35) + (notes . "README.adoc, META/ECOSYSTEM/STATE.scm, comprehensive SECURITY.md"))) (testing ((status . "minimal") @@ -62,13 +67,16 @@ (core-functionality ((status . "in-progress") (completion . 25) - (notes . "Initial implementation underway"))))) + (notes . "Rust core with profile/activity/schedule modules, TypeScript shell scaffolded"))))) (working-features ("RSR-compliant CI/CD pipeline" "Multi-platform mirroring (GitHub, GitLab, Bitbucket)" "SPDX license headers on all files" - "SHA-pinned GitHub Actions")))) + "SHA-pinned GitHub Actions" + "CodeQL security scanning" + "OSSF Scorecard integration" + "Security policy enforcement workflow")))) ;;;============================================================================ ;;; ROUTE TO MVP @@ -151,6 +159,15 @@ (define session-history '((snapshots + ((date . "2025-12-17") + (session . "security-hardening-review") + (accomplishments + ("Fixed critical HTTP/HTTPS detection bug in security-policy.yml" + "SHA-pinned scorecard.yml actions for supply chain security" + "Updated RSR validation to support README.adoc and LICENSE.txt" + "Reviewed all SCM files for correctness" + "Updated STATE.scm with current project status")) + (notes . "Security audit and SCM review session")) ((date . "2025-12-15") (session . "initial-state-creation") (accomplishments @@ -185,10 +202,10 @@ (define state-summary '((project . "double-track-browser") (version . "0.1.0") - (overall-completion . 25) + (overall-completion . 30) (next-milestone . "v0.2 - Core Functionality") (critical-blockers . 0) (high-priority-issues . 0) - (updated . "2025-12-15"))) + (updated . "2025-12-17"))) ;;; End of STATE.scm diff --git a/justfile b/justfile index 90c1766..5f2d026 100644 --- a/justfile +++ b/justfile @@ -182,8 +182,8 @@ validate-rsr: echo "📋 Checking RSR compliance..." echo "" echo "Documentation:" - [[ -f README.md ]] && echo " ✅ README.md" || echo " ❌ README.md" - [[ -f LICENSE ]] && echo " ✅ LICENSE" || echo " ❌ LICENSE" + [[ -f README.adoc || -f README.md ]] && echo " ✅ README" || echo " ❌ README" + [[ -f LICENSE.txt || -f LICENSE ]] && echo " ✅ LICENSE" || echo " ❌ LICENSE" [[ -f SECURITY.md ]] && echo " ✅ SECURITY.md" || echo " ❌ SECURITY.md" [[ -f CODE_OF_CONDUCT.md ]] && echo " ✅ CODE_OF_CONDUCT.md" || echo " ❌ CODE_OF_CONDUCT.md" [[ -f CONTRIBUTING.md ]] && echo " ✅ CONTRIBUTING.md" || echo " ❌ CONTRIBUTING.md"