Skip to content

feat(security): harden Git SSH and publish vulnerability SARIF - #179

Draft
richards-ensono wants to merge 3 commits into
mainfrom
improve-openssf-crypto-analysis
Draft

richards-ensono wants to merge 3 commits into
mainfrom
improve-openssf-crypto-analysis

Conversation

@richards-ensono

@richards-ensono richards-ensono commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • harden Git-over-SSH with explicit supported key exchange, cipher, MAC, host-key, and public-key authentication policy;

  • warn, without rejecting or replacing the selected identity, when an SSH key is undersized or cannot be classified safely;

  • add evidence-backed OpenSSF Best Practices answers and retain crypto_keylength as Unmet because warnings do not disable undersized keys;

  • emit govulncheck SARIF and upload it to GitHub code scanning for GitHub-managed triage, mitigation, and risk acceptance.

  • move shared coding-agent guidance into root AGENTS.md and rename the project automation skill to .agents/skills/task-runner, including the verified rootless Podman DOCKER_HOST / EIRCTL_DOCKER_HOST setup.

Validation

  • go test ./...
  • go run -race cmd/main.go run lints with the verified rootless Podman socket (DOCKER_HOST and EIRCTL_DOCKER_HOST)
  • go test ./scripts/check-workflow-policy
  • scripts/check-immutable-ci-dependencies.sh
  • openspec validate improve-openssf-crypto-analysis --json
  • pre-commit run --all-files

Compatibility and risk posture

@richards-ensono
richards-ensono requested a review from a team as a code owner September 28, 2026 09:54
@richards-ensono
richards-ensono force-pushed the improve-openssf-crypto-analysis branch from ed8ad12 to bed5586 Compare September 28, 2026 09:54
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@sonarqubecloud

Copy link
Copy Markdown

@richards-ensono
richards-ensono marked this pull request as draft September 28, 2026 10:30
@richards-ensono richards-ensono self-assigned this Sep 28, 2026
@richards-ensono richards-ensono added the security Issues and pull requests that materially affect security label Sep 28, 2026
@@ -0,0 +1,184 @@
package config

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if possible can we change this package to be config_test and change this struct hardenedGitSSHAuth to be public - it's in an internal package so it's never exported outside the module - all the methods on it are public and it would be easier to maintain tests only tested via a public API

Comment thread eirctl.yaml
@@ -44,7 +44,8 @@ pipelines:
- task: go:lint
- task: go:vuln:check

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this will be replaced by trivy anyway in this PR #165 as the go vuln checker is a bit bare and limiting in terms of outputs and filtering capability

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Issues and pull requests that materially affect security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants