Repository navigation
feat(security): harden Git SSH and publish vulnerability SARIF - #179
richards-ensono wants to merge 3 commits into
Conversation
ed8ad12 to
bed5586
Compare
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
| @@ -0,0 +1,184 @@ | |||
| package config | |||
There was a problem hiding this comment.
if possible can we change this package to be config_test and change this struct hardenedGitSSHAuth to be public - it's in an internal package so it's never exported outside the module - all the methods on it are public and it would be easier to maintain tests only tested via a public API
| @@ -44,7 +44,8 @@ pipelines: | |||
| - task: go:lint | |||
| - task: go:vuln:check | |||
There was a problem hiding this comment.
this will be replaced by trivy anyway in this PR #165 as the go vuln checker is a bit bare and limiting in terms of outputs and filtering capability



Summary
harden Git-over-SSH with explicit supported key exchange, cipher, MAC, host-key, and public-key authentication policy;
warn, without rejecting or replacing the selected identity, when an SSH key is undersized or cannot be classified safely;
add evidence-backed OpenSSF Best Practices answers and retain
crypto_keylengthas Unmet because warnings do not disable undersized keys;emit
govulncheckSARIF and upload it to GitHub code scanning for GitHub-managed triage, mitigation, and risk acceptance.move shared coding-agent guidance into root
AGENTS.mdand rename the project automation skill to.agents/skills/task-runner, including the verified rootless PodmanDOCKER_HOST/EIRCTL_DOCKER_HOSTsetup.Validation
go test ./...go run -race cmd/main.go run lintswith the verified rootless Podman socket (DOCKER_HOSTandEIRCTL_DOCKER_HOST)go test ./scripts/check-workflow-policyscripts/check-immutable-ci-dependencies.shopenspec validate improve-openssf-crypto-analysis --jsonpre-commit run --all-filesCompatibility and risk posture
StrictHostKeyChecking=nobehavior are retained.crypto_keylengthremains Unmet: weak keys are only warned about, not blocked.