feat: rebuild local provenance, security, and review workflow (TAB-18–29) - #47
Conversation
Entire-Checkpoint: 95aae876ef91
Entire-Checkpoint: 95aae876ef91
|
Linked to Plane Work Item(s) References
This comment was auto-generated by Plane |
Plane-Work-Item: TAB-19 Entire-Checkpoint: 95aae876ef91
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d929ab2781
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
…48) * feat: normalize candidate-bound provenance source snapshots Plane-Work-Item: TAB-21 Entire-Checkpoint: 95aae876ef91 * fix: select comparison base for manual quality checks Plane-Work-Item: TAB-21 Entire-Checkpoint: 95aae876ef91 * feat: replay source evidence with safe review and recovery (TAB-22–29) (#49) * feat: rebuild provenance from pinned source snapshots Plane-Work-Item: TAB-22 Entire-Checkpoint: 95aae876ef91 * feat: explicit provenance verdicts and safe review (TAB-23–29) (#50) * feat: preserve safe source failure reasons in review packets Plane-Work-Item: TAB-23 Entire-Checkpoint: 95aae876ef91 * feat: exact-candidate packets, security, and review (TAB-24–29) (#51) * fix: enforce complete review packet bounds and candidate acceptance Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88 * test: validate review packets with the native schema checker Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88 * feat: exact security evidence, review, and recovery (TAB-26–29) (#52) * feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 88ed14083a
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
…18–29) Entire-Checkpoint: 3a4c8131eec1
Entire-Checkpoint: 3a4c8131eec1
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aefa341a1b
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Entire-Checkpoint: ab2c360fdf7c
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 79f0861097
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Entire-Checkpoint: ab2c360fdf7c
Entire-Checkpoint: ab2c360fdf7c
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8cb5218755
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Entire-Checkpoint: ab2c360fdf7c
Entire-Checkpoint: ab2c360fdf7c
Entire-Checkpoint: ab2c360fdf7c
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 95ad82e45b
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Plane-Work-Item: TAB-18 Entire-Checkpoint: ab2c360fdf7c
Plane-Work-Item: TAB-18 Entire-Checkpoint: ab2c360fdf7c
Plane-Work-Item: TAB-18 Entire-Checkpoint: ab2c360fdf7c
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 30e8c3020b
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| requireFact(pr?.number === context.selection.pullRequestNumber, "record_missing"); | ||
| requireFact(snapshot.repositoryId === context.candidate.repositoryId, "scope_mismatch"); | ||
| requireFact(pr.source?.commit === context.candidate.headCommit && pr.target?.commit === context.candidate.baseCommit, "candidate_mismatch"); | ||
| requireFact(pr.state === "open" && !pr.draft, "review_not_ready"); |
There was a problem hiding this comment.
Require the draft flag to be exactly false
When an imported GitHub snapshot contains a malformed falsy draft value such as null or 0, !pr.draft treats it as proof that the pull request is ready, so an otherwise matching approval produces a passed review observation and can satisfy the gate once security evidence is added. Require pr.draft === false or validate the complete GitHub snapshot contract before accepting it.
Useful? React with 👍 / 👎.
| if (files.size >= 4096 || totalBytes > 32 * 1024 * 1024) throw new Error("Candidate exceeds security scan bounds."); | ||
| const target = join(directory, path); | ||
| await mkdir(dirname(target), { recursive: true }); | ||
| await writeFile(target, blob.stdout, { mode: 0o600 }); |
There was a problem hiding this comment.
Detect filesystem aliases before materializing scan files
On the supported default case-insensitive macOS filesystem, a Git tree containing distinct paths such as A.js and a.js causes these writes to target the same file; because tree order can write a clean blob after a secret-bearing blob, both scanners inspect only the clean content and can issue a passing receipt. The fresh evidence in this revision is that fatal UTF-8 decoding still materializes valid names directly and therefore does not prevent case or Unicode-normalization aliases; reject colliding paths or scan each blob in an alias-free namespace.
Useful? React with 👍 / 👎.
| const review = await readInput(options.input); | ||
| const secured = attachSecurityReview({ lineage, review, policyDigest: options.policyDigest, now }); | ||
| const digest = await store.putLineage(secured); | ||
| await writeJsonOutput({ status: review.status, candidate, digest, securityDigest: review.digest }, options.out); |
There was a problem hiding this comment.
Protect provenance outputs from input aliases
When import-security receives an --out path that directly, through a hard link, or through a symbolic link aliases its --input receipt, this write succeeds after the database import but replaces the full security receipt with the short import summary. The stored lineage retains only the derived security observation, so the original findings can no longer be supplied to review --security-input; validate output paths against every input before writing, as the other evidence CLIs do.
Useful? React with 👍 / 👎.
| "artifactCount" | ||
| ], | ||
| "properties": { | ||
| "id": {"type": "string", "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"}, |
There was a problem hiding this comment.
Version the Buildkite schema before adding build IDs
When an existing consumer validates new collector output with the previously published buildkite-build-snapshot/v0.1 schema, the newly emitted id field is rejected because that version's build object used additionalProperties: false and did not declare this property. Changing the closed v0.1 contract in place makes producer output incompatible with consumers pinned to the same advertised schema version; preserve v0.1 and introduce a new schema version for snapshots containing build IDs.
Useful? React with 👍 / 👎.
Rebuild Tabellio’s local provenance workflow: bounded private metadata, local PostgreSQL persistence, exact Git candidate identity, source-attributed fixture readers, deterministic replay, explicit evidence verdicts, safe review packets, separate security checks, and guarded CLI/GitHub status publication. Child PRs #48–55 are integrated.
The sample uses real Git and PostgreSQL, exercises restart and clean-store replay, and covers 11 failure cases. Provider records and GitHub status transport in the sample remain synthetic. Publication approval consumption uses unique compare-and-swap reservations on a verified private GitHub.com control repository. Security scans cover the entire immutable Git tree, including when invoked from a subdirectory; candidate capture rejects ambiguous merge bases.
Buildkite’s hosted macOS queue was incompatible with the organization’s Personal plan. The existing bootstrap and all pipeline jobs now use linux-small. Per-job setup provides supported Git and PostgreSQL; database-backed validation runs as an unprivileged user. All required checks are retained.
Validated candidate:
30e8c3020bb7f818666c29e2d98395c362135d16. Exact local gate, hosted Product and Quality, real sample demo, four bounded security checks over the application’s immutable content, and native review gate passed. Buildkite #178 passed all six steps. All 25 known inline review findings are fixed and resolved.Plane: TAB-18 through TAB-29. TAB-21 requires fixture normalization; TAB-27 includes matching blocked CLI/GitHub results. This does not claim complete live-provider provenance, release publication, deployment, a Neon migration, or a web dashboard. Release requires a separate human decision.