Skip to content

fix(rules): see quoted and flow-style uses: in KYAML workflows - #896

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/kyaml-quoted-uses
Oct 1, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/kyaml-quoted-uses

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

PinIntegrity (@uses_regex, pin_integrity.ex:56) and research rules RE001 / RE003 / RE005 read workflows as block-style text. On a KYAML workflow (YAML-POLICY Y-3, the estate base form, e.g. yq -o kyaml) they could not see anything:

Form Before
uses: "owner/repo@sha", # v1 not a pin site (quote, comma)
{ uses: "owner/repo@sha" }, not a pin site ({ anchor)
step items opened by a bare { RE001 found no job steps, RE005 no steps, RE003 no quoted actions/cache

The blindness was measured before the fix: on main, 6 of the 10 new KYAML cases fail, and the KYAML PI001 mutant passes unnoticed (4 red on the old regex).

How

  • pin_integrity: a tolerant regex. It accepts an optional quote (closed by a backreference), a leading { and a trailing } / ,. The key must still open the line (after indentation and an optional - / {), so a uses: inside a run: string is not a site (decoy test). substitute_denylisted_pins keeps rewriting the original bytes, and the quote and comma survive.
  • research_extensions: read_workflow/1 → flow_to_block/1 rewrites KYAML to the equivalent block layout one line for one line: closers become blank lines, key: { drops its opener, - goes on a sequence item's first key, and trailing commas and plain quotes are removed. Finding line numbers therefore still point at the source. The rewrite applies only when the first significant line is a bare {, so block YAML (including its own on: [push] and permissions: {}) passes through byte-identical, and the existing suites confirm it. No new file is added under lib/rules/, so the module count stays at 33.

Tests

  • test/kyaml_workflow_test.exs: per rule, a positive, a control and (for pin sites) a run:-string decoy; a single-quoted variant; the block-style control.
  • test/rules/pin_integrity_test.exs: a KYAML PI001 mutant, caught at its physical line and then repaired in place.
  • Full suite: 1768 tests, 0 failures. The 242 :verisim_data tests are excluded, as always (Known Gaps 3). mix format --check-formatted is clean.

Not in scope (recorded, not fixed here)

RE002, RE004, RE006–RE010 and the composite-action uses: scan (re006, ~r/^\s*-?\s*uses:\s*(\S+)/m) still read raw text. They could adopt read_workflow/1 in a follow-up, each with its own KYAML tests. RE003's uses: actions/cache match is content-wide, so a run: body mentioning it counts. That is pre-existing for block YAML, and unquoting makes it reachable from KYAML too.

🤖 Generated with Claude Code

https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS

pin_integrity's @uses_regex and research rules RE001/RE003/RE005 read
workflows as block-style text. On a KYAML workflow (YAML-POLICY Y-3, the
estate base form: `uses: "owner/repo@sha", # v1`, `{ uses: "..." },`,
step items opened by a bare `{`) they saw nothing: no pin sites, no jobs,
no steps. Planted tests confirmed it: 6 of the 10 KYAML cases were red on
main, and the PI001 mutant was missed.

- pin_integrity: the regex accepts an optional quote (matched by a
  backreference), a leading `{`, and a trailing `}`/`,`. The key must
  still open the line, so a `uses:` inside a `run:` string is not a site.
  Substitution keeps the quote and comma intact.
- research_extensions: read_workflow/1 + flow_to_block/1 rewrite KYAML to
  the equivalent block layout one line for one line, so finding line
  numbers still point at the source. A file whose first significant
  line is not a bare `{` passes through byte-identical. RE001, RE003 and
  RE005 read through it.

Tests: test/kyaml_workflow_test.exs (positive, control and decoy per
rule) plus a KYAML PI001 mutant/repair case. Full suite: 1768 tests,
0 failures (242 :verisim_data excluded, as always).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 1, 2026 22:22
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6b830a6a-31d9-493b-8864-7db6fb3cbde2

📥 Commits

Reviewing files that changed from the base of the PR and between 51ab649 and d649bee.

📒 Files selected for processing (4)
  • lib/rules/pin_integrity.ex
  • lib/rules/research_extensions.ex
  • test/kyaml_workflow_test.exs
  • test/rules/pin_integrity_test.exs
 _____________________________________________________________
< Please stop using global state like it's a communal fridge. >
 -------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit d6eade9 into main Oct 1, 2026
39 of 44 checks passed
@hyperpolymath
hyperpolymath deleted the fix/kyaml-quoted-uses branch October 1, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant