fix(ci): detect orphaned Actions workflow identities - #279
Draft
seonghobae wants to merge 20 commits into
Draft
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #278.
Boundary
This Draft is the read-only Actions workflow-registry evidence lane. The detector never calls GitHub, reads credentials, disables/restores workflows, mutates refs, or creates workflow-control authority. Operational workflow disablement remains an authorized control-plane action after a fresh complete registry observation.
Protected
mainis independently resolved ate8109ec2a17de8bd6594487aa12c8c8a93cb2c03. The PR metadata base is historical (a430b1c153702de3b6439def801732d7453b4940); exact comparison against live protected main reports this branch diverged, 20 commits ahead / 5 behind. This branch is therefore not integrated-live-base proof and must remain Draft.Detector contract
Exact repair-owner evidence — RED → GREEN
A fresh audit found that
ownedActiveRepairPathscould classify an active workflow identity asowned_active_repairusing only its path. That did not retain the exact PR/head authority supporting the exemption and therefore weakened acquisition/control-plane evidence.Hosted RED —
a9f207cccad000521bcbca9a2a170ca96f55fd1eTest-only
src/actionsWorkflowRegistryAuditRepairOwnership.test.tsrequired legacy path-only repair exemptions to fail closed and structured{ path, prNumber, headSha }evidence to be retained in output. CI31827066178, build/test job94853582276, checked out that exact SHA, completed immutable install and typecheck, then failed exactly the two new assertions while the pre-existing suite remained green.Contract migration —
81bccd014ef5231219887420d61283d73a597b66The existing registry-audit fixture was migrated to the same exact repair-owner contract; no production relaxation was introduced.
GREEN — current exact head
955e5228446926f0583ef08f434431a757584f79Production now accepts only optional
ownedActiveRepairs, where every exemption is an exact object containing a canonical workflow path, positive safe-integer PR number, and lowercase 40-hex head SHA. Duplicate repair paths fail closed.owned_active_repairevidence includes the exact{ prNumber, headSha }owner. Legacy path-only input is rejected by the strict top-level contract. The detector remains offline/read-only and gains no credential, ref, workflow-disable, network, or execution authority.Exact-head proof and browser RCA
For unchanged head
955e5228446926f0583ef08f434431a757584f79:31827389419: completed / success after same-SHA retry;clipboard.browser.spec.tsbeforeEachafter a 20 s timeout, before the detector could influence browser behavior;94855718608then completed success, including the real-engine rich-clipboard evidence;a9f207...had also passed the browser lane, supporting transient WebKit startup/setup RCA rather than a detector regression;At this evidence generation, exact-head Security Scan
31827389442and SAST Semgrep31827389440remain queued / non-passing. Queued, pending, skipped, cancelled, absent, predecessor, status-only, and model-only evidence is not represented as passing proof.Integration boundary
Live organization policy requires one qualifying independent approval, last-push approval by someone other than the pusher, review-thread resolution, and all applicable central required workflows. The exact current branch is also 5 protected-main commits behind, and this invocation has no supported non-destructive branch-sync mutation; that exact reconciliation action is therefore unavailable rather than inferred as repository state. Do not force-push, destructively rebase, or manufacture merge/tag/release identity.
Issue #118 continues to own exact
v0.6.0publication from protected main. Fresh Actions registry observation remains larger than protected-main workflow source inventory; operational disablement must use a fresh complete registry snapshot and preserve current repair/dynamic identities. Any source-head or live-base movement invalidates this evidence.