Skip to content

fix(security): resolve CodeQL include alert #1309 and Scorecard SAST alert #6 (ADR-1389) - #1659

Merged
lusoris merged 1 commit into
masterfrom
fix/code-scanning-include-and-sast
Oct 1, 2026
Merged

lusoris merged 1 commit into
masterfrom
fix/code-scanning-include-and-sast

Conversation

@lusoris

@lusoris lusoris commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Closes two open code-scanning alerts on master:

  1. CodeQL alert fix(ci): stop the tracked-venv gate from matching basenames that merely start with venv #1309 (cpp/include-non-header): Replaces unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c with direct linkage against libvmaf in core/test/meson.build and narrow internal test accessors in core/src/libvmaf_priv.h / core/src/libvmaf.c. Adds scripts/ci/check-no-non-header-includes.sh to pre-commit and CI rule enforcement to prevent future non-header includes under core/test/.
  2. Scorecard alert chore(deps): Update dependency anthropic to >=0.104.1 #6 (SASTID): Under ADR-1389, runs CodeQL (Actions) unconditionally on every pull request and push to master in .github/workflows/security-scans.yml, ensuring 100% commit SAST coverage across docs-only and non-code PRs with negligible (~15–20s) overhead, enforced in .github/workflows/required-aggregator.yml.

Type

  • fix — bug fix
  • build / ci — tooling / infra

Checklist

  • Commits follow Conventional Commits (the commit-msg hook enforces this).
  • make format && make lint is green locally.
  • Unit tests pass: python3 scripts/ci/run_meson_test.py -- -C build.
  • If I touched any SIMD/GPU code path, I ran /cross-backend-diff and the worst ULP is ≤ 2.
  • If I touched a feature extractor with SIMD/GPU twins, I either updated every twin or listed the gap under "Known follow-ups" below.
  • If I added a new .c / .cpp / .cu / .h / .hpp, it has the appropriate license header (see CONTRIBUTING.md).
  • If this is a breaking change, the commit message uses ! or BREAKING CHANGE: and the migration path is documented below.
  • If this PR adds an ADR, the ADR row lives in docs/adr/_index_fragments/<NNNN-slug>.md and the slug is appended to docs/adr/_index_fragments/_order.txt — do not edit docs/adr/README.md directly (regenerated by scripts/docs/concat-adr-index.sh; see ADR-0221).

Bug-status hygiene (ADR-0165)

  • docs/state.md updated in this PR with a row in the appropriate section (Open / Recently closed / Confirmed not-affected / Deferred), OR no state delta: REASON.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.
  • If I believe a golden value must change, I have explained why below AND pinged @lusoris for a CODEOWNERS exception.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: previously documented in docs/research/2093-codeql-include-non-header-alerts.md (PR fix(rc1): integrate pre-RC1 correctness train #1561)
  • Decision matrix — captured in the corresponding ADR's ## Alternatives considered in ADR-1389.
  • AGENTS.md invariant note — added to scripts/ci/AGENTS.md documenting check-no-non-header-includes.sh.
  • Reproducer / smoke-test command — pasted below under "Reproducer".
  • CHANGELOG fragment — changelog.d/fixed/code-scanning-include-and-sast.md added.
  • Rebase note — entry added to docs/rebase-notes.md under fix/code-scanning-include-and-sast.

Reproducer

bash scripts/ci/check-no-non-header-includes.sh
bash scripts/ci/tests/test-check-no-non-header-includes.sh
./build/test/test_feature_backend_twin
python3 scripts/ci/run_meson_test.py -- -C build test_feature_backend_twin

Known follow-ups

Alerts #1 (CodeReview) and #1054 (BranchProtection) are structural organization-level settings and remain out of scope for this code PR.

@github-actions github-actions Bot added the type:bug Something isn't working label Oct 1, 2026
@lusoris
lusoris force-pushed the fix/code-scanning-include-and-sast branch from cf20eb8 to 4cf5c4b Compare October 1, 2026 08:21
…alert #6 (ADR-1389)

- Resolve CodeQL alert #1309 (cpp/include-non-header):
  Replace unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c
  with direct linkage against libvmaf in core/test/meson.build and narrow internal test
  accessors in core/src/libvmaf_priv.h (vmaf_backend_twin_verdict_for_test,
  vmaf_context_fake_backend_for_test, vmaf_context_set_gpumask_for_test,
  vmaf_context_append_registered_feature_extractor_for_test, and
  vmaf_context_resolve_context_fallbacks_for_test) implemented statically in
  core/src/libvmaf.c.
- Add scripts/ci/check-no-non-header-includes.sh and test suite
  scripts/ci/tests/test-check-no-non-header-includes.sh, wired into
  .pre-commit-config.yaml and .github/workflows/rule-enforcement.yml to fail
  closed on non-header source inclusions in core/test/.
- Resolve OpenSSF Scorecard alert #6 (SAST):
  Under ADR-1389, run CodeQL (Actions) unconditionally on every pull request and
  master push in .github/workflows/security-scans.yml, ensuring 100% commit SAST
  coverage across docs-only and non-code PRs with negligible (~15-20s) overhead,
  and enforce it in .github/workflows/required-aggregator.yml.
- Update docs/state.md, changelog fragment, docs/rebase-notes.md, and ADR index.
@lusoris
lusoris force-pushed the fix/code-scanning-include-and-sast branch from 4cf5c4b to 2564e5d Compare October 1, 2026 08:36
@lusoris
lusoris merged commit c66d28b into master Oct 1, 2026
65 of 69 checks passed
@lusoris
lusoris deleted the fix/code-scanning-include-and-sast branch October 1, 2026 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant