Repository navigation
修復 Git 中繼資料污染及同版本空範本快取 - #3
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
根因與修正範圍
原生索引器將 Git 中繼資料、README/圖示占位檔配置為未命名範本;相同來源 commit 的快取捷徑又保留錯誤索引。另有合法根 README 被誤當版本目錄的共同解析缺口。
.git,在配置版本前驗證數字/semver。config.yml/template.yml建立範本身分;保留先讀取的 metadata,未有有效定義的占位項目不輸出。前次正式候選 CI 已完成兩輪功能、race、39 項 integration 與相同位元封裝,但安全 gate 揭露 pip 內嵌的 urllib3 仍是有漏洞的 2.7.0;安裝頂層 urllib3 並不能修復它。此候選以官方 uninstall/APT purge 在準備後退役 pip、tox、virtualenv 與 build-only 套件,直接執行原有 flake8/pytest,保留兩份 hash locks、19 項測試依賴、開發者 tox.ini 與 Go/race 流程。沒有 autoremove、修改 vendored 程式、刪除 SBOM 或新增 urllib3 例外。
OpenVEX 只綁定當前 82 個 kernel-header finding/PURL;新 CI 必須證明安裝器實作/seed 已不存在、19 項依賴與 wheel hashes 完全相符、產品掃描通過及兩輪成品相同。沒有宣稱建置期間零漏洞。
實際驗證與未完成事項
v1.6.514整合、8080 部署與完整權限矩陣尚未通過;不部署公司環境、不修改 HAProxy、不用 runtime patch。