-
Notifications
You must be signed in to change notification settings - Fork 0
fix(security): fail closed when dependency-review compare is unavailable #1041
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
6 commits
Select commit
Hold shift + click to select a range
285bb39
fix(security): fail closed on unavailable dependency review
seonghobae 241ef9d
fix(security): record visibility on dependency-review fail-closed
cursoragent 887bf99
test(security): prove 403 skip and transport failure cannot go green
cursoragent cef601e
test(security): keep bash resolvable in the dependency-review probe h…
cursoragent 46706a3
fix(security): reject malformed dependency-review identity before com…
cursoragent c2e79c8
test(security): pin identity-failure logs to omit raw SHA and repo
cursoragent File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,64 @@ | ||
| # Dependency review fail-closed operations | ||
|
|
||
| Status: `active_pr` until the matching workflow and regression contract are present on protected `main`; thereafter `implemented_on_protected_main`. | ||
|
|
||
| ## Decision | ||
|
|
||
| Dependency review is a hard supply-chain gate. The central workflow accepts only HTTP `200` from GitHub's exact `BASE_SHA...HEAD_SHA` comparison before invoking the immutably pinned dependency-review action. A `403`, `404`, empty or malformed status, timeout, transport failure, truncated exchange, or other unexpected outcome is unavailable evidence and fails closed. | ||
|
|
||
| The support probe has a 10-second connection limit and 30-second total limit. It preserves curl's transport exit code separately from the bounded HTTP status and requires transport exit `0` plus exact HTTP `200`. It rejects a base or head revision that is not exactly 40 or 64 hexadecimal characters, and a repository name that is not canonical `owner/name` without `.` or `..` segments, before any network call (curl exit `uncalled`). Identity-validation failures name the failure class only and do not echo the raw invalid values. It discards the response body and, after a successful identity check, logs repository identity, allowlisted visibility (`public`, `private`, `internal`, or `unknown`), exact base/head revisions, the normalized HTTP status, and the numeric transport exit. An HTTP `000` no-status sentinel is unavailable evidence. Credentials, response bodies, and raw untrusted visibility strings are never diagnostic output. After a successful probe the pinned action is not independently skippable. Executable regressions record the exact compare argv so a hardcoded `supported=true` path cannot satisfy the success contract. | ||
|
|
||
| RFC 9110 §15.3.1 defines `200` as a completed successful representation, not as a status that can be inferred after a truncated transfer (Fielding et al., 2022). NIST SP 800-53 Rev. 5 RA-5 and SA-12 require that vulnerability and supply-chain evidence be obtained, not assumed absent (National Institute of Standards and Technology, 2020). SLSA v1.0 likewise treats missing provenance as unverified rather than passing (SLSA, 2023). An HTTP `403` or `404` is therefore unavailable evidence, not a clean skip. | ||
|
|
||
| ## Identity and authority | ||
|
|
||
| The dependency-review job checks out the pull request's explicit head repository and immutable head SHA with persisted credentials disabled. The API comparison independently binds the event's exact base and head revisions. The job retains `contents: read` and `pull-requests: read`; it receives no write, OIDC, model, release, package, or deployment authority. | ||
|
|
||
| Checks, status contexts, review submissions, and merge authorization remain separate evidence classes. OSV, Trivy, CodeQL, Semgrep, Secret Scan, Scorecard, and Dependabot are complementary controls and are not semantic substitutes for dependency review. | ||
|
|
||
| ## Failure classification and remediation | ||
|
|
||
| - Transport exit `0` plus HTTP `200`: proceed to the pinned dependency-review action. | ||
| - Malformed revision or repository: fail closed with HTTP `unavailable` and curl exit `uncalled` before opening a socket. Resupply the pull request's exact hex SHAs and canonical `owner/name`, then rerun. Do not echo the raw invalid values. | ||
| - Any other result: fail the job and retain exact repository, allowlisted visibility, base/head, status, and transport-exit evidence. An HTTP `200` emitted by a failed or partial transfer, or an HTTP `000` sentinel, is unavailable evidence. Do not infer a root cause from HTTP `403` or `404`. | ||
| - Public repository failure: verify dependency graph and security configuration, organization policy, token read access, and GitHub service health. | ||
| - Private or internal exception: require a separately reviewed organization policy with explicit entitlement evidence and compensating controls. Never infer `not-applicable` from an unavailable response. | ||
|
|
||
| Retries are operator-initiated only after the capability or service condition changes. Do not rerun unchanged evidence repeatedly and do not convert an unavailable endpoint into a green skip. | ||
|
|
||
| ## Known canary | ||
|
|
||
| ContextualWisdomLab/EgressWeave#66, Security Scan run `31108241013`, job `92638903658`, compared `10d0c51daf2ad278d66f43be479df8cf6b08ba6d...c038a9509d1a8eae8561cc9081e67e12bd373d42` and received HTTP `403`. The required workflow printed the skip warning, omitted `actions/dependency-review-action`, and still concluded success. Downstream tracking: ContextualWisdomLab/EgressWeave#76. Keep ContextualWisdomLab/.github#810 open until a protected-main public consumer run proves a non-200 or failed-transfer comparison cannot green this job. | ||
|
|
||
| ## Acceptance and rollback | ||
|
|
||
| Acceptance requires the permanent queue contract to reject the former `supported=false` path, require bounded probing and discarded bodies, require exact-head checkout, reject malformed revisions and repository names before the network call, prove the success path invoked the exact compare URL, and prove that only `200` reaches the action. Exact-head CI/security evidence, current review, protected integration, and a real protected-main consumer run remain required. | ||
|
|
||
| Rollback requires an independently reviewed revert and fresh exact-head evidence. A rollback must not restore the `403`/`404` success path or print an API response body. | ||
|
|
||
| ## References | ||
|
|
||
| Berners-Lee, T., Fielding, R., & Masinter, L. (2005). *Uniform Resource | ||
| Identifier (URI): Generic syntax* (RFC 3986). Internet Engineering Task | ||
| Force. https://doi.org/10.17487/RFC3986 | ||
|
|
||
| Fielding, R., Nottingham, M., & Reschke, J. (Eds.). (2022). *HTTP semantics* | ||
| (RFC 9110). Internet Engineering Task Force. https://doi.org/10.17487/RFC9110 | ||
|
|
||
| GitHub. (n.d.). *Dependency review*. GitHub Docs. Retrieved August 9, 2026, from https://docs.github.com/en/code-security/concepts/supply-chain-security/dependency-review | ||
|
|
||
| GitHub. (n.d.). *REST API endpoints for dependency review*. GitHub Docs. Retrieved August 9, 2026, from https://docs.github.com/en/rest/dependency-graph/dependency-review | ||
|
|
||
| GitHub. (n.d.). *Dependency graph*. GitHub Docs. Retrieved August 9, 2026, from https://docs.github.com/en/code-security/concepts/supply-chain-security/dependency-graph | ||
|
|
||
| GitHub. (n.d.). *Webhook events and payloads*. GitHub Docs. Retrieved August 16, 2026, from https://docs.github.com/en/webhooks/webhook-events-and-payloads#repository | ||
|
|
||
| MITRE. (n.d.). *CWE-20: Improper input validation*. Retrieved August 16, | ||
| 2026, from https://cwe.mitre.org/data/definitions/20.html | ||
|
|
||
| National Institute of Standards and Technology. (2020). *Security and | ||
| privacy controls for information systems and organizations* (NIST SP | ||
| 800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5 | ||
|
|
||
| SLSA. (2023). *SLSA v1.0: Supply-chain Levels for Software Artifacts*. | ||
| Open Source Security Foundation. https://slsa.dev/spec/v1.0/ |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The probe starts curl immediately after the visibility allowlist. An empty
BASE_SHA, a 39-character hex string, or../inHEAD_SHAis interpolated into/dependency-graph/compare/{base}...{head}. The executable harness then returns HTTP 200 and the step writessupported=true.Reject 40- or 64-character hex revisions and canonical
owner/namebeforeset +e, and fail with HTTPunavailable/ curl exituncalled. Landed on #1045.