fix(osv): preserve immutable direct-source provenance - #1158
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent review exact current head |
|
@opencode-agent Keep this PR Draft and repair the current exact head
Also remove the self-trust exception in |
|
Revalidated PR #1158 after repairing the current-head provenance contract. Root-cause fixes:
Exact-head proof:
Please rerun independent review and all protected Checks for this exact head. The PR remains subject to branch protection; no merge is claimed. |
|
@opencode-agent review exact current head |
|
@opencode-agent review this exact current HEAD. Use the current commit SHA, current Checks, and current diff; do not reuse prior approvals or prior-head evidence. |
|
Inkspan downstream canary is ready for this existing owner lane; no consumer-side suppression/workaround has been introduced. Fresh bindings before this note:
After this exact owner repair integrates into protected |
|
Security root-cause fix at current head e2c0031: malformed UTF-8 is now rejected at the shared text-input boundary with an explicit fail-closed ValueError, covering lockfile and JSON audit/results inputs. Added regression coverage; local 15 tests, Ruff, compileall, and diff checks passed. Please run the independent current-head review and required checks for this exact SHA. |
|
@opencode-agent please review current HEAD e2c0031 for PR #1158; focus on malformed input handling, fail-closed provenance, and security regressions. |
|
Fresh consumer-owner revalidation identifies a live exact-identity contradiction that must be corrected on this existing central writer before Inkspan can reuse it. GitHub PR metadata currently resolves #1158 as head Exact-head workflow evidence for actual head Consumer remains Inkspan #318 at unchanged Smallest owner action remains on this existing #1158 branch: reconcile non-destructively onto the then-live protected central base, resolve the integrity trust boundary with a falsifiable regression that distinguishes a merely well-formed forged digest from artifact-byte-verified provenance (or narrow the reconciliation claim so it cannot rely on unverified integrity), regenerate all required exact-head central workflows to terminal success, then update the PR's exact identity/evidence prose to the actual head/base. Only after protected integration should Inkspan #318 receive a fresh Security Scan; predecessor central or Inkspan results must not transfer. |
|
Fresh Inkspan consumer revalidation for this existing OSV owner lane; no Inkspan suppression, dependency rename, or competing central writer was created. Consumer identity is unchanged: Fresh owner-state refetch supersedes this PR body's older identity: The smallest safe owner action remains dependency-order repair of #1158 against then-current protected central main without force-push/destructive history, preserving its eight-path OSV ownership boundary and excluding the separate pip-audit writer. Then regenerate the complete exact-head central gate/review set. Only after an accepted equivalent repair is protected-main truth should Inkspan #318 rerun Security Scan on unchanged/descendant exact head. Consumer GREEN acceptance is specific: the reporter must no longer classify official immutable |
Preserve the immutable direct-source reconciler while adopting the protected-main cross-fork checkout boundary. Bind base and head provenance to source/pnpm-lock.yaml so scan and reconciliation identities remain coherent.
|
Protected main is now integrated non-destructively at exact head The conflict exposed a real cross-fork provenance boundary: protected main confines both checkouts/scans to RED: focused merge contract failed because the old broad
Fresh hosted workflows are queued and remain non-passing until terminal. Inkspan #318 stays the downstream acceptance canary; no consumer source was changed. Exact-current-head formal review remains required. @opencode-agent review |
Require the exact SHA-512 receipt for the governed SheetJS 0.20.3 tarball. A merely well-formed but unrelated digest now fails closed instead of authorizing advisory reconciliation.
|
Exact-head evidence for
Please provide a formal Reviews API verdict bound to this exact head. Predecessor reviews/checks are not counted. |
|
Inkspan #318 dependency revalidation on the current owner state:
No duplicate source writer or redispatch is needed; converge the existing owner PR's live identity, evidence, and unresolved-thread state before lifecycle action. |
|
@opencode-agent please perform a fresh formal review of exact head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
e61fb11fbd5c7464d34cc8bedc3a7177fbdcade2. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32636946163/job/97188058523)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32636946163/job/97188058523)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: osv-direct-source-provenance.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: osv-direct-source-provenance.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script: osv_direct_source_reconcile.py"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script: osv_direct_source_reconcile.py"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: osv-direct-source-provenance.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: osv-direct-source-provenance.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script: osv_direct_source_reconcile.py"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script: osv_direct_source_reconcile.py"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
e61fb11fbd5c7464d34cc8bedc3a7177fbdcade2. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32636946163/job/97188058523)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32636946163/job/97188058523)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: osv-direct-source-provenance.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: osv-direct-source-provenance.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script: osv_direct_source_reconcile.py"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script: osv_direct_source_reconcile.py"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
|
Exact head |
|
@opencode-agent review Please publish an independent substantive formal Reviews API verdict for exact current head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
88b6859f2edabfb65f2bbac32460b5341c3980c0. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32718073334/job/97403470177)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32718073334/job/97403470177)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: osv-direct-source-provenance.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: osv-direct-source-provenance.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script: osv_direct_source_reconcile.py"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script: osv_direct_source_reconcile.py"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
88b6859f2edabfb65f2bbac32460b5341c3980c0. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32718073334/job/97403470177)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32718073334/job/97403470177)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: osv-direct-source-provenance.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: osv-direct-source-provenance.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script: osv_direct_source_reconcile.py"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script: osv_direct_source_reconcile.py"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
Tracks #1096; do not close until protected-main integration and fresh Inkspan canary acceptance.
Problem and fail-closed contract
The reusable Security Scan previously passed OSV's npm name/version result to the reporter without preserving direct-tarball URL and integrity evidence. Open-ended npm ranges could therefore attribute already-remediated advisories to an official immutable vendor release.
This repair:
xlsxreleases, including 0.18.x, 0.19.2, and 0.20.1;xlsx@0.20.3provenance whose authoritative affected range excludes it;SCANNER_METADATA_CONFLICTevidence;O_NOFOLLOWand regular-file validation;packagesmap, not provenance-free snapshot duplicates;source.pathfor the governed root lockfile;Exact identity and evidence
97361089cab8c16bb94ecaa0ea01db9c6aed56b4.main@0c6b9a6459c9dbdf5e23fb01df7a32a8a14964b3.OSErrorescapedmain()as an unstructured traceback.::error::non-passing diagnostics.97333898737, checked out exact9736108, passed 1,422 tests·70 subtests, and measured 100% statements/branches.fce8fe72ebf4d438c17a7c889dd37c92118c6204; its historical Security Scan failure is not acceptance evidence.Decision:
WAIT_FOR_TERMINAL_EXACT_HEAD_CHECKS_FORMAL_REVIEW_MAIN_INTEGRATION_AND_INKSPAN_CANARY.