Repository navigation
fix: remediate scorecard alerts - #161
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✅ Files skipped from review due to trivial changes (1)
WalkthroughこのPRは、CodeQLのPRトリガー拡大、Scorecard注釈追加、インストールスクリプトの自動npmフォールバック削除、配布アーカイブの必須バイナリ追加、TOMLパーサ向けGo fuzzテスト、及び証跡とCHANGELOGの追加を行います。 ChangesCI/CD Security Configuration
Installation Script Hardening
Binary Artifact Tracking
Config Robustness Testing
Evidence and Changelog Documentation
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Validation note: local checks passed (shell syntax, YAML parse, distribution archive, Go package tests, fuzz smoke, full Go suite, validate-plugin, check-consistency). Codex companion review found no blocking correctness/security/performance/maintainability issues. GitHub correctly rejects self-approval, so this PR needs an independent human approval to satisfy the new branch protection and improve Scorecard Code-Review history. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/evidence/scorecard-alerts-2026-05-27.md`:
- Around line 57-73: The validation block has two reproducibility issues: the
YAML check uses a root-relative path for scorecard.yml and the repeated "cd go
&& go test ..." lines change the working directory across commands causing
subsequent runs to fail; update the Python YAML loader to open the
repository-local file (e.g., use "./scorecard.yml" in the list inside the
python3 heredoc where it iterates over for path in [...]) and consolidate the
three "cd go && go test ..." invocations so the directory change is done once
(e.g., run all go tests within a single subshell or use pushd/popd) rather than
repeating "cd go &&" per test to ensure subsequent commands run from the
expected directory.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 4a7943fd-6516-4447-860b-12de887b98e7
📒 Files selected for processing (9)
.github/workflows/codeql.ymlCHANGELOG.mdbin/.gitignoredocs/evidence/scorecard-alerts-2026-05-27.mdgo/pkg/config/toml_fuzz_test.goscorecard.ymlscripts/check-codex.shscripts/quick-install.shtests/test-distribution-archive.sh
💤 Files with no reviewable changes (1)
- .github/workflows/codeql.yml
| ```bash | ||
| bash -n scripts/quick-install.sh scripts/check-codex.sh | ||
| git diff --check | ||
| python3 - <<'PY' | ||
| import yaml | ||
| for path in ['scorecard.yml', '.github/workflows/codeql.yml']: | ||
| with open(path, 'r', encoding='utf-8') as f: | ||
| yaml.safe_load(f) | ||
| print(path, 'ok') | ||
| PY | ||
| bash tests/test-distribution-archive.sh | ||
| cd go && go test ./pkg/config | ||
| cd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/config | ||
| cd go && go test ./... | ||
| bash tests/validate-plugin.sh | ||
| bash scripts/ci/check-consistency.sh | ||
| ``` |
There was a problem hiding this comment.
検証コマンドの再現性を修正してください。
2点あります。scorecard.yml のパスがルート相対で誤っており、cd go && ... を連続実行すると2回目以降に失敗します。証跡の再実行性に直結するので、このブロックは修正した方がよいです。
💡 修正例
python3 - <<'PY'
import yaml
-for path in ['scorecard.yml', '.github/workflows/codeql.yml']:
+for path in ['.github/workflows/scorecard.yml', '.github/workflows/codeql.yml']:
with open(path, 'r', encoding='utf-8') as f:
yaml.safe_load(f)
print(path, 'ok')
PY
bash tests/test-distribution-archive.sh
-cd go && go test ./pkg/config
-cd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/config
-cd go && go test ./...
+(cd go && go test ./pkg/config)
+(cd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/config)
+(cd go && go test ./...)
bash tests/validate-plugin.sh
bash scripts/ci/check-consistency.sh🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/evidence/scorecard-alerts-2026-05-27.md` around lines 57 - 73, The
validation block has two reproducibility issues: the YAML check uses a
root-relative path for scorecard.yml and the repeated "cd go && go test ..."
lines change the working directory across commands causing subsequent runs to
fail; update the Python YAML loader to open the repository-local file (e.g., use
"./scorecard.yml" in the list inside the python3 heredoc where it iterates over
for path in [...]) and consolidate the three "cd go && go test ..." invocations
so the directory change is done once (e.g., run all go tests within a single
subshell or use pushd/popd) rather than repeating "cd go &&" per test to ensure
subsequent commands run from the expected directory.
|
Update: code scanning policy dismissals completed for Binary-Artifacts #2-#5 and CII-Best-Practices #12 as 'won't fix' with comments. Branch-Protection #1 is fixed. Remaining open Scorecard alerts are the PR-backed fixes waiting to land (#7-#10 Pinned-Dependencies, #13 Fuzzing, #14 SAST) plus #11 Code-Review, which needs independent human-approved merge history. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/test-codex-package.sh`:
- Around line 617-620: The test currently searches for the string 'versioned /
pinned update flow' (rg check) but prints an unrelated error message
"package-manager fallback guidance"; update the echo so it accurately reflects
the missing check (e.g., mention "versioned / pinned update flow" or similar) in
the block that sets permission_policy_ok=false—locate the rg invocation that
uses '--fixed-strings' with 'versioned / pinned update flow' and change the
corresponding echo text to match that same phrase so the failure message and the
checked pattern are consistent.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: a863649a-7c5d-4918-a7cb-d38d783e223e
📒 Files selected for processing (1)
tests/test-codex-package.sh
| if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then | ||
| echo " missing: scripts/check-codex.sh package-manager fallback guidance" | ||
| permission_policy_ok=false | ||
| fi |
There was a problem hiding this comment.
エラーメッセージの更新が必要です。
Line 617でチェックしている内容("versioned / pinned update flow")とLine 618のエラーメッセージ("package-manager fallback guidance")が一致していません。テストが失敗した際、開発者が実際に不足している内容を正確に把握できるよう、エラーメッセージを更新することを推奨します。
💬 エラーメッセージの修正案
if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then
- echo " missing: scripts/check-codex.sh package-manager fallback guidance"
+ echo " missing: scripts/check-codex.sh versioned/pinned update flow guidance"
permission_policy_ok=false
fi📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then | |
| echo " missing: scripts/check-codex.sh package-manager fallback guidance" | |
| permission_policy_ok=false | |
| fi | |
| if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then | |
| echo " missing: scripts/check-codex.sh versioned/pinned update flow guidance" | |
| permission_policy_ok=false | |
| fi |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@tests/test-codex-package.sh` around lines 617 - 620, The test currently
searches for the string 'versioned / pinned update flow' (rg check) but prints
an unrelated error message "package-manager fallback guidance"; update the echo
so it accurately reflects the missing check (e.g., mention "versioned / pinned
update flow" or similar) in the block that sets
permission_policy_ok=false—locate the rg invocation that uses '--fixed-strings'
with 'versioned / pinned update flow' and change the corresponding echo text to
match that same phrase so the failure message and the checked pattern are
consistent.
Summary
harness.tomlparsing and require shipped platform binaries in the distribution archive check.External repo setting applied
mainbranch protection:actionlint,validate,test-goValidation
bash -n scripts/quick-install.sh scripts/check-codex.shgit diff --checkscorecard.ymland.github/workflows/codeql.ymlbash tests/test-distribution-archive.shcd go && go test ./pkg/configcd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/configcd go && go test ./...bash tests/validate-plugin.shbash scripts/ci/check-consistency.shbash scripts/codex-companion.sh review --base origin/main: no blocking findingsSummary by CodeRabbit
リリースノート
テスト
ドキュメント
その他
メタ情報