-
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(security): upgrade crossbeam-epoch from 0.9.18 to 0.9.20 #95
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
d2a1000
3af827d
8d5a8fc
87317d9
971a1f9
8def598
64a5662
7d380cf
26ff801
4ee2310
7912859
8d5e52f
589171f
312d36e
dfa6f8a
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,6 +16,7 @@ on: | |
| - cron: '0 6 * * 1' # Weekly on Monday | ||
|
|
||
| permissions: read-all | ||
| actions: read | ||
|
|
||
| jobs: | ||
| audit: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,7 @@ on: | |
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| pages: write | ||
| id-token: write | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -8,6 +8,7 @@ on: | |
| branches: [ main, develop ] | ||
|
|
||
| permissions: read-all | ||
| actions: read | ||
|
|
||
| env: | ||
| CARGO_TERM_COLOR: always | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -18,6 +18,7 @@ concurrency: | |
| cancel-in-progress: true | ||
|
|
||
| permissions: | ||
| actions: read | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/codeql.yml
printf '%s\n' '--- workflow files ---'
git ls-files '.github/workflows/*'Repository: hyperpolymath/filesoup Length of output: 2720 🤖 get_repo_knowledge executed:
Length of output: 600 🌐 Web query:
💡 Result: <search_synthesis> <source_evidence> Citations:
🏁 Script executed: cat -n .github/workflows/codeql.ymlRepository: hyperpolymath/filesoup Length of output: 1964 🌐 Web query:
💡 Result: <search_synthesis> <source_evidence> Citations:
🏁 Script executed: set -eu
python3 - <<'PY'
import json, urllib.request
for url in [
'https://raw.githubusercontent.com/github/codeql-action/29b1f65c1f735799893313399435a59f54045865/action.yml',
'https://raw.githubusercontent.com/github/codeql-action/29b1f65c1f735799893313399435a59f54045865/analyze/action.yml',
]:
print('---', url, '---')
try:
with urllib.request.urlopen(url, timeout=10) as response:
text = response.read().decode()
for i, line in enumerate(text.splitlines(), 1):
if 'permission' in line.lower() or 'actions' in line.lower() or 'security-events' in line.lower():
print(f'{i}:{line}')
except Exception as exc:
print(type(exc).__name__, str(exc))
PYRepository: hyperpolymath/filesoup Length of output: 686 Declare The job-level 🧰 Tools🪛 zizmor (1.29.0)[warning] 21-21: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment (undocumented-permissions) 🤖 Prompt for AI AgentsSource: MCP tools |
||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
@@ -39,12 +40,12 @@ jobs: | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3 | ||
| uses: github/codeql-action/init@29b1f65c1f735799893313399435a59f54045865 # v3 | ||
| with: | ||
| languages: ${{ matrix.language }} | ||
| build-mode: ${{ matrix.build-mode }} | ||
|
|
||
| - name: Perform CodeQL Analysis | ||
| uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3 | ||
| uses: github/codeql-action/analyze@29b1f65c1f735799893313399435a59f54045865 # v3 | ||
| with: | ||
| category: "/language:${{ matrix.language }}" | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -41,7 +41,8 @@ on: | |
| types: [opened, reopened, synchronize] | ||
|
|
||
| permissions: | ||
| contents: write # needed to enable auto-merge | ||
| actions: read | ||
| contents: read # needed to enable auto-merge | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: printf '%s\n' '--- workflow ---'; cat -n .github/workflows/dependabot-automerge.yml; printf '%s\n' '--- related workflow references ---'; rg -n --hidden -g '.github/**' -e 'dependabot-automerge|gh pr merge|pull-requests:|contents:|GITHUB_TOKEN|github.token|token:' .github || trueRepository: hyperpolymath/filesoup Length of output: 10091 🤖 get_repo_knowledge executed:
Length of output: 1340 🌐 Web query:
💡 Result: <search_synthesis> <source_evidence> Citations:
Set This 🤖 Prompt for AI AgentsSource: MCP tools |
||
| pull-requests: write # needed to approve | ||
| # NB: keep narrow — do NOT add secrets: read or id-token: write here. | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -13,6 +13,7 @@ on: | |
| branches: [main, master] | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -9,6 +9,7 @@ on: | |
| types: [published] | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,12 @@ | ||
| name: Central Estate CI/CD Audit | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win Declare the caller permissions explicitly. The checked-in workflow linter rejects workflow files without a top-level permissions:
contents: read🧰 Tools🪛 zizmor (1.29.0)[warning] 1-13: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) 🤖 Prompt for AI Agents |
||
|
|
||
| on: | ||
| push: | ||
| branches: [ "main" ] | ||
| pull_request: | ||
| branches: [ "main" ] | ||
| workflow_call: | ||
|
|
||
| jobs: | ||
| call-estate-audit: | ||
| uses: hyperpolymath/cicd-suite/.github/workflows/main-estate-audit.yml@feat/cicd-workflow-call | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: set -eu
printf '%s\n' '--- workflow hunk ---'
sed -n '1,24p' .github/workflows/main-estate-audit.yml
printf '%s\n' '--- referenced branch resolution ---'
python3 - <<'PY'
import json, urllib.request
url = "https://api.github.com/repos/hyperpolymath/cicd-suite/git/ref/heads/feat/cicd-workflow-call"
req = urllib.request.Request(url, headers={"Accept": "application/vnd.github+json", "User-Agent": "review-verifier"})
try:
with urllib.request.urlopen(req, timeout=10) as r:
data = json.load(r)
print(json.dumps({"ref": data.get("ref"), "object": data.get("object")}, sort_keys=True))
except Exception as e:
print(type(e).__name__ + ": " + str(e))
PYRepository: hyperpolymath/filesoup Length of output: 620 🤖 get_repo_knowledge executed:
Length of output: 1048 🏁 Script executed: set -eu
python3 - <<'PY'
import json, subprocess, sys
base = "https://api.github.com/repos/hyperpolymath/cicd-suite"
ref_url = base + "/git/ref/heads/feat/cicd-workflow-call"
cmd = ["curl", "-ksS", "-H", "Accept: application/vnd.github+json", "-A", "review-verifier", ref_url]
raw = subprocess.check_output(cmd, text=True)
print("--- branch ref response ---")
print(raw)
try:
data = json.loads(raw)
except json.JSONDecodeError:
sys.exit(0)
sha = data.get("object", {}).get("sha")
if sha:
commit_url = base + "/commits/" + sha
verified = subprocess.check_output(
["curl", "-ksS", "-H", "Accept: application/vnd.github+json", "-A", "review-verifier", commit_url],
text=True,
)
print("--- commit resolution ---")
try:
c = json.loads(verified)
print(json.dumps({"requested_sha": sha, "resolved_sha": c.get("sha"), "message": c.get("commit", {}).get("message", "").splitlines()[0]}, sort_keys=True))
except json.JSONDecodeError:
print(verified)
PYRepository: hyperpolymath/filesoup Length of output: 825 Security Misconfiguration Reachability: External Pin the reusable workflow to commit The branch reference is mutable and can execute unreviewed workflow code with this repository’s token. 🧰 Tools🪛 zizmor (1.29.0)[warning] 1-13: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 11-13: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI Agents |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,7 @@ name: Push email notification | |
| on: | ||
| push: {} | ||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| jobs: | ||
| notify: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,7 @@ on: | |
| - 'v*' | ||
|
|
||
| permissions: read-all | ||
| actions: read | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win Fix the permission block indentation. Both actionlint 1.7.12 and YAMLlint 1.37.1 report 🧰 Tools🪛 actionlint (1.7.12)[error] 10-10: could not parse as YAML: mapping values are not allowed in this context (syntax-check) 🪛 YAMLlint (1.37.1)[error] 10-10: syntax error: mapping values are not allowed here (syntax) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
|
|
||
| env: | ||
| CARGO_TERM_COLOR: always | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -10,11 +10,12 @@ on: | |
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| security-events: write | ||
| id-token: write | ||
|
Comment on lines
+13
to
+14
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value Remove the unused workflow-level write permissions as optional future-proofing. The 🧰 Tools🪛 zizmor (1.29.0)[warning] 13-13: overly broad permissions (excessive-permissions): security-events: write is overly broad at the workflow level (excessive-permissions) [error] 14-14: overly broad permissions (excessive-permissions): id-token: write is overly broad at the workflow level (excessive-permissions) [warning] 13-13: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment (undocumented-permissions) 🤖 Prompt for AI Agents |
||
| jobs: | ||
| analysis: | ||
| permissions: | ||
| security-events: write | ||
| id-token: write | ||
| uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 | ||
| uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@1f3eef621985b2dd0e7e2d3ac265c0f0ba6b0a78 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- caller workflow ---'
cat -n .github/workflows/scorecard.yml
printf '%s\n' '--- local workflow references ---'
rg -n -C 3 'scorecard-reusable|secrets: inherit|workflow_call' .github/workflows
printf '%s\n' '--- reusable workflow contract at pinned revision ---'
curl -fsSL 'https://raw.githubusercontent.com/hyperpolymath/standards/1f3eef621985b2dd0e7e2d3ac265c0f0ba6b0a78/.github/workflows/scorecard-reusable.yml' | cat -nRepository: hyperpolymath/filesoup Length of output: 10002 Sensitive Data Exposure Reachability: External Remove The called workflow declares no 🧰 Tools🪛 zizmor (1.29.0)[warning] 20-20: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow (secrets-inherit) 🤖 Prompt for AI AgentsSource: MCP tools |
||
| secrets: inherit | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,52 @@ | ||
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| name: Security Policy | ||
| on: | ||
| push: | ||
| branches: [main, master] | ||
| pull_request: | ||
|
|
||
| # Estate guardrail: scope push to default branches so a PR fires once (not | ||
| # push+PR), and cancel superseded runs. Safe — read-only PR-triggered check. | ||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| permissions: | ||
| contents: read | ||
| jobs: | ||
| check: | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 15 | ||
| permissions: | ||
| contents: read | ||
| steps: | ||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| - name: Security checks | ||
| run: | | ||
| FAILED=false | ||
|
|
||
| # Block MD5/SHA1 for security (allow for checksums/caching) | ||
| WEAK_CRYPTO=$(grep -rE 'md5\(|sha1\(' --include="*.py" --include="*.rb" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" . 2>/dev/null | grep -v 'checksum\|cache\|test\|spec' | head -5 || true) | ||
| if [ -n "$WEAK_CRYPTO" ]; then | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -e
file=".github/workflows/security-policy.yml"
wc -l "$file"
cat -n "$file"Repository: hyperpolymath/filesoup Length of output: 2609 Security Misconfiguration Reachability: External Make each detected policy violation fail the workflow. When either scan finds a match, set 🤖 Prompt for AI Agents |
||
| echo "⚠️ Weak crypto (MD5/SHA1) detected. Use SHA256+ for security:" | ||
| echo "$WEAK_CRYPTO" | ||
| fi | ||
|
|
||
| # Block HTTP URLs (except localhost) | ||
| HTTP_URLS=$(grep -rE 'http://[^l][^o][^c]' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.yaml" --include="*.yml" . 2>/dev/null | grep -v 'localhost\|127.0.0.1\|example\|test\|spec' | head -5 || true) | ||
| if [ -n "$HTTP_URLS" ]; then | ||
| echo "⚠️ HTTP URLs found. Use HTTPS:" | ||
| echo "$HTTP_URLS" | ||
| fi | ||
|
|
||
| # Hardcoded secrets check removed: redundant with secret-scanner.yml workflow | ||
| # which uses gitleaks for more accurate secret detection with fewer false positives. | ||
| # The secrets check was causing false positives on test fixtures and examples. | ||
|
|
||
| if [ "$FAILED" = true ]; then | ||
| exit 1 | ||
| fi | ||
|
|
||
| echo "✅ Security policy check passed" | ||
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -24,7 +24,7 @@ jobs: | |||||
| errors=0 | ||||||
| for f in .github/workflows/*.yml .github/workflows/*.yaml; do | ||||||
| [ -f "$f" ] || continue | ||||||
| if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then | ||||||
| if ! awk '/^---[[:space:]]*$/ { next } /^#/ { print; next } { exit }' \"\$f\" \| grep -q \"^# SPDX-License-Identifier:\"; then | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win Remove the shell escapes from the SPDX command. The escaped Proposed fix- if ! awk '/^---[[:space:]]*$/ { next } /^`#/` { print; next } { exit }' \"\$f\" \| grep -q \"^# SPDX-License-Identifier:\"; then
+ if ! awk '/^---[[:space:]]*$/ { next } /^`#/` { print; next } { exit }' "$f" | grep -q "^# SPDX-License-Identifier:"; then📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||
| echo "ERROR: $f missing SPDX header" | ||||||
| errors=$((errors + 1)) | ||||||
| fi | ||||||
|
|
||||||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Use one valid
permissionsform in both workflows.Each changed line adds a mapping entry beneath an existing scalar permissions declaration. YAML cannot parse this structure. GitHub Actions cannot load the affected workflows.
.github/workflows/cargo-audit.yml#L19-L19: removeactions: readbecauseread-allalready includes it, or replaceread-allwith a complete permissions mapping..github/workflows/ci.yml#L11-L11: removeactions: reador convert the existing permissions value to a valid complete mapping.🧰 Tools
🪛 actionlint (1.7.12)
[error] 19-19: could not parse as YAML: mapping values are not allowed in this context
(syntax-check)
🪛 YAMLlint (1.37.1)
[error] 19-19: syntax error: mapping values are not allowed here
(syntax)
📍 Affects 2 files
.github/workflows/cargo-audit.yml#L19-L19(this comment).github/workflows/ci.yml#L11-L11🤖 Prompt for AI Agents
Source: Linters/SAST tools