Skip to content

fix: remediate scorecard alerts - #161

Merged
Chachamaru127 merged 3 commits into
mainfrom
codex/scorecard-alert-triage
May 27, 2026
Merged

Chachamaru127 merged 3 commits into
mainfrom
codex/scorecard-alert-triage

Conversation

@Chachamaru127

@Chachamaru127 Chachamaru127 commented May 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Remove mutable global npm install/update fallbacks from quick install and Codex update guidance.
  • Expand CodeQL so SAST runs on every main push and PR instead of only Go-path changes.
  • Add a Go fuzz target for harness.toml parsing and require shipped platform binaries in the distribution archive check.
  • Add OSSF Scorecard maintainer annotations plus an evidence snapshot for alert disposition.

External repo setting applied

  • Enabled main branch protection:
    • required checks: actionlint, validate, test-go
    • required approvals for non-admin merges: 1
    • force push: disabled
    • branch deletion: disabled
    • admin enforcement: disabled, to preserve release marker operations

Validation

  • bash -n scripts/quick-install.sh scripts/check-codex.sh
  • git diff --check
  • YAML parse for scorecard.yml and .github/workflows/codeql.yml
  • bash tests/test-distribution-archive.sh
  • cd go && go test ./pkg/config
  • cd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/config
  • cd go && go test ./...
  • bash tests/validate-plugin.sh
  • bash scripts/ci/check-consistency.sh
  • bash scripts/codex-companion.sh review --base origin/main: no blocking findings

Summary by CodeRabbit

リリースノート

  • テスト

    • TOML 設定パーサー向けのファジング検証を追加
    • 配布アーカイブに含める必須バイナリ検証を強化
  • ドキュメント

    • Scorecard のセキュリティアラート証跡を追加
    • 変更履歴(Changelog)に関連情報を追記
  • その他

    • CodeQL の実行が main への push に加え main 向け PR でも走るよう拡大
    • インストールスクリプトの自動フォールバック案内を削除し手動案内へ変更
    • 配布バイナリの追跡設定を更新し Windows 実行ファイルを反映
  • メタ情報

    • Scorecard 注釈のメタ情報を追加

Review Change Stack

@coderabbitai

coderabbitai Bot commented May 27, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 803e0516-b665-43ca-985d-2436115abc6c

📥 Commits

Reviewing files that changed from the base of the PR and between 8b26549 and bbebb7d.

📒 Files selected for processing (1)
  • docs/evidence/scorecard-alerts-2026-05-27.md
✅ Files skipped from review due to trivial changes (1)
  • docs/evidence/scorecard-alerts-2026-05-27.md

Walkthrough

このPRは、CodeQLのPRトリガー拡大、Scorecard注釈追加、インストールスクリプトの自動npmフォールバック削除、配布アーカイブの必須バイナリ追加、TOMLパーサ向けGo fuzzテスト、及び証跡とCHANGELOGの追加を行います。

Changes

CI/CD Security Configuration

Layer / File(s) Summary
CodeQL trigger expansion and Scorecard annotations
.github/workflows/codeql.yml, scorecard.yml
Pull request trigger for CodeQL workflow now runs for PRs targeting main. scorecard.yml adds annotations (binary-artifacts: remediated, cii-best-practices: not-applicable).

Installation Script Hardening

Layer / File(s) Summary
Dependency installation flow enforcement
scripts/quick-install.sh, scripts/check-codex.sh, tests/test-codex-package.sh
AST-Grep npm fallback removed (Homebrew or manual guidance shown). TypeScript Language Server automatic npm install removed in favor of manual/versioned guidance. Codex update fallback messaging changed to “versioned / pinned update flow” and tests updated accordingly.

Binary Artifact Tracking

Layer / File(s) Summary
Platform binary artifact management
bin/.gitignore, tests/test-distribution-archive.sh
bin/.gitignore adjusted to track the shipped platform binary set; distribution archive test now requires bin/harness-{darwin-amd64,darwin-arm64,linux-amd64,windows-amd64.exe}.

Config Robustness Testing

Layer / File(s) Summary
TOML parser fuzz testing
go/pkg/config/toml_fuzz_test.go
Add FuzzParseBytes fuzz test targeting config.ParseBytes with seeded TOML inputs and an 8192-byte length guard.

Evidence and Changelog Documentation

Layer / File(s) Summary
Scorecard alert evidence and branch protection snapshot
docs/evidence/scorecard-alerts-2026-05-27.md
Add evidence document listing Scorecard alerts, branch protection JSON, verification commands/results, and references.
Changelog entries for post-release updates
CHANGELOG.md
Update Unreleased Changed/Fixed/Security entries describing CodeQL coverage expansion, fuzz seed addition, archive policy, npm fallback removal, Scorecard annotations, and evidence doc.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Poem

🐰 ぴょんと跳ねて知らせるよ、
CodeQLは今や全PRへ、
npm自動はそっと外し、
バイナリは揃えて検査、
証跡残してまた耕すよ。

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed プルリクエストのタイトル「fix: remediate scorecard alerts」は、Scorecard アラートの修復という主要な変更内容を正確に反映しており、記載されている複数の変更内容(CodeQL 設定の拡張、npm のフォールバック削除、Go fuzz テストの追加、バイナリ配布ポリシーの整備、Scorecard annotations の追加)の統括的な目的を明確に示しています。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/scorecard-alert-triage

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Chachamaru127

Copy link
Copy Markdown
Owner Author

Validation note: local checks passed (shell syntax, YAML parse, distribution archive, Go package tests, fuzz smoke, full Go suite, validate-plugin, check-consistency). Codex companion review found no blocking correctness/security/performance/maintainability issues. GitHub correctly rejects self-approval, so this PR needs an independent human approval to satisfy the new branch protection and improve Scorecard Code-Review history.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/evidence/scorecard-alerts-2026-05-27.md`:
- Around line 57-73: The validation block has two reproducibility issues: the
YAML check uses a root-relative path for scorecard.yml and the repeated "cd go
&& go test ..." lines change the working directory across commands causing
subsequent runs to fail; update the Python YAML loader to open the
repository-local file (e.g., use "./scorecard.yml" in the list inside the
python3 heredoc where it iterates over for path in [...]) and consolidate the
three "cd go && go test ..." invocations so the directory change is done once
(e.g., run all go tests within a single subshell or use pushd/popd) rather than
repeating "cd go &&" per test to ensure subsequent commands run from the
expected directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 4a7943fd-6516-4447-860b-12de887b98e7

📥 Commits

Reviewing files that changed from the base of the PR and between 828c9ed and 4a16f5c.

📒 Files selected for processing (9)
  • .github/workflows/codeql.yml
  • CHANGELOG.md
  • bin/.gitignore
  • docs/evidence/scorecard-alerts-2026-05-27.md
  • go/pkg/config/toml_fuzz_test.go
  • scorecard.yml
  • scripts/check-codex.sh
  • scripts/quick-install.sh
  • tests/test-distribution-archive.sh
💤 Files with no reviewable changes (1)
  • .github/workflows/codeql.yml

Comment on lines +57 to +73
```bash
bash -n scripts/quick-install.sh scripts/check-codex.sh
git diff --check
python3 - <<'PY'
import yaml
for path in ['scorecard.yml', '.github/workflows/codeql.yml']:
with open(path, 'r', encoding='utf-8') as f:
yaml.safe_load(f)
print(path, 'ok')
PY
bash tests/test-distribution-archive.sh
cd go && go test ./pkg/config
cd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/config
cd go && go test ./...
bash tests/validate-plugin.sh
bash scripts/ci/check-consistency.sh
```

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

検証コマンドの再現性を修正してください。

2点あります。scorecard.yml のパスがルート相対で誤っており、cd go && ... を連続実行すると2回目以降に失敗します。証跡の再実行性に直結するので、このブロックは修正した方がよいです。

💡 修正例
 python3 - <<'PY'
 import yaml
-for path in ['scorecard.yml', '.github/workflows/codeql.yml']:
+for path in ['.github/workflows/scorecard.yml', '.github/workflows/codeql.yml']:
     with open(path, 'r', encoding='utf-8') as f:
         yaml.safe_load(f)
     print(path, 'ok')
 PY
 bash tests/test-distribution-archive.sh
-cd go && go test ./pkg/config
-cd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/config
-cd go && go test ./...
+(cd go && go test ./pkg/config)
+(cd go && go test -run '^$' -fuzz=FuzzParseBytes -fuzztime=3s ./pkg/config)
+(cd go && go test ./...)
 bash tests/validate-plugin.sh
 bash scripts/ci/check-consistency.sh
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/evidence/scorecard-alerts-2026-05-27.md` around lines 57 - 73, The
validation block has two reproducibility issues: the YAML check uses a
root-relative path for scorecard.yml and the repeated "cd go && go test ..."
lines change the working directory across commands causing subsequent runs to
fail; update the Python YAML loader to open the repository-local file (e.g., use
"./scorecard.yml" in the list inside the python3 heredoc where it iterates over
for path in [...]) and consolidate the three "cd go && go test ..." invocations
so the directory change is done once (e.g., run all go tests within a single
subshell or use pushd/popd) rather than repeating "cd go &&" per test to ensure
subsequent commands run from the expected directory.

@Chachamaru127

Copy link
Copy Markdown
Owner Author

Update: code scanning policy dismissals completed for Binary-Artifacts #2-#5 and CII-Best-Practices #12 as 'won't fix' with comments. Branch-Protection #1 is fixed. Remaining open Scorecard alerts are the PR-backed fixes waiting to land (#7-#10 Pinned-Dependencies, #13 Fuzzing, #14 SAST) plus #11 Code-Review, which needs independent human-approved merge history.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test-codex-package.sh`:
- Around line 617-620: The test currently searches for the string 'versioned /
pinned update flow' (rg check) but prints an unrelated error message
"package-manager fallback guidance"; update the echo so it accurately reflects
the missing check (e.g., mention "versioned / pinned update flow" or similar) in
the block that sets permission_policy_ok=false—locate the rg invocation that
uses '--fixed-strings' with 'versioned / pinned update flow' and change the
corresponding echo text to match that same phrase so the failure message and the
checked pattern are consistent.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a863649a-7c5d-4918-a7cb-d38d783e223e

📥 Commits

Reviewing files that changed from the base of the PR and between 4a16f5c and 8b26549.

📒 Files selected for processing (1)
  • tests/test-codex-package.sh

Comment on lines +617 to 620
if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then
echo " missing: scripts/check-codex.sh package-manager fallback guidance"
permission_policy_ok=false
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

エラーメッセージの更新が必要です。

Line 617でチェックしている内容("versioned / pinned update flow")とLine 618のエラーメッセージ("package-manager fallback guidance")が一致していません。テストが失敗した際、開発者が実際に不足している内容を正確に把握できるよう、エラーメッセージを更新することを推奨します。

💬 エラーメッセージの修正案
 if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then
-  echo "  missing: scripts/check-codex.sh package-manager fallback guidance"
+  echo "  missing: scripts/check-codex.sh versioned/pinned update flow guidance"
   permission_policy_ok=false
 fi
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then
echo " missing: scripts/check-codex.sh package-manager fallback guidance"
permission_policy_ok=false
fi
if ! rg -q --fixed-strings 'versioned / pinned update flow' "scripts/check-codex.sh"; then
echo " missing: scripts/check-codex.sh versioned/pinned update flow guidance"
permission_policy_ok=false
fi
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/test-codex-package.sh` around lines 617 - 620, The test currently
searches for the string 'versioned / pinned update flow' (rg check) but prints
an unrelated error message "package-manager fallback guidance"; update the echo
so it accurately reflects the missing check (e.g., mention "versioned / pinned
update flow" or similar) in the block that sets
permission_policy_ok=false—locate the rg invocation that uses '--fixed-strings'
with 'versioned / pinned update flow' and change the corresponding echo text to
match that same phrase so the failure message and the checked pattern are
consistent.

@Chachamaru127
Chachamaru127 merged commit 9acbf00 into main May 27, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant