Skip to content

fix(security): resolve CodeQL config merge conflict, add Go CodeQL coverage (ADR-0811) - #171

Closed
lusoris wants to merge 1 commit into
masterfrom
security/codeql-go-pvr-fixes-20260529
Closed

lusoris wants to merge 1 commit into
masterfrom
security/codeql-go-pvr-fixes-20260529

Conversation

@lusoris

@lusoris lusoris commented May 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bug fix: Resolves two unresolved Git conflict markers in .github/codeql-config.yml left from the libvmaf/ → core/ rename (ADR-0700). The conflict caused all CodeQL jobs to consume a syntactically-broken config; GitHub CodeQL silently falls back to scanning everything when config is invalid.
  • Coverage gap closed: Adds codeql-go job to security-scans.yml covering the Phase 4 Go surface (cmd/, pkg/, api/ — vmafx-controller, vmafx-mcp, vmafx-node, pkg/ai/infer.go). SHA-pinned to the codeql-action v4 already in use; excludes gen/go (generated protobuf stubs).
  • OSSF posture documented: ADR-0811 records the Dependabot/Renovate decision: Renovate with osvVulnerabilityAlerts: true is the operative mechanism (Dependabot superseded by ADR-0363); no code change needed.

Audit findings answered

Question Finding
Vulnerability disclosure policy? Yes — SECURITY.md (root) with 72h ACK / 30-day fix SLA, GH private advisory URL, PGP email.
Private vulnerability reports enabled? Repo is private; GitHub PVR is a public-repo feature (API returned 422/404). Moot.
Dependabot config sane? dependabot.yml.disabled correctly superseded by Renovate (ADR-0363); osvVulnerabilityAlerts: true in renovate.json.
OSSF Scorecard current? scorecard.yml runs weekly, publishes to dashboard, SHA-pinned at ossf/scorecard-action@4eaacf0543.
CodeQL languages? After this PR: C/C++, Python, Actions, Go (new). Rust: follow-up when CodeQL Rust support GAs.

Deep-dive deliverables (ADR-0108)

  • Research digest: no digest needed — gap-fill CI fix
  • Decision matrix: in ADR-0811 ## Alternatives considered
  • AGENTS.md invariant: no rebase-sensitive invariants
  • Reproducer: python3 -c "import yaml; yaml.safe_load(open('.github/codeql-config.yml'))" — previously raised on conflict markers; now passes
  • Changelog fragment: changelog.d/security/0811-codeql-go-config-fix.md
  • Rebase notes: no rebase impact: CI-config-only

Test plan

  • Verify CodeQL (Go) job appears in Actions tab after merge
  • Verify CodeQL (C/C++) and CodeQL (Python) jobs no longer show "invalid config" warnings
  • Confirm check yaml pre-commit passes (already verified locally in this commit)

🤖 Generated with Claude Code

@lusoris
lusoris force-pushed the security/codeql-go-pvr-fixes-20260529 branch from 8b98726 to b49d147 Compare May 29, 2026 11:31
@lusoris
lusoris marked this pull request as draft May 29, 2026 11:48
…(ADR-0811)

- Resolve unresolved git conflict markers in .github/codeql-config.yml
  left from the libvmaf/ -> core/ rename; adopt core/ layout in full.
- Extend CodeQL paths to cover the Phase 4 Go surface (cmd/, pkg/, api/);
  exclude gen/go (generated protobuf stubs).
- Add codeql-go job to security-scans.yml covering vmafx-controller,
  vmafx-mcp, vmafx-node, and pkg/ai/infer.go with security-and-quality
  suite; SHA-pinned to the same codeql-action v4 already in use.
- Document Dependabot/Renovate posture: Renovate osvVulnerabilityAlerts
  is the operative alert mechanism (Dependabot superseded by ADR-0363).

no rebase impact: CI-config-only change; no public API surface affected.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris force-pushed the security/codeql-go-pvr-fixes-20260529 branch from b49d147 to b6dc61f Compare May 29, 2026 12:12
@lusoris

lusoris commented May 29, 2026

Copy link
Copy Markdown
Contributor Author

Pre-rebase check (batch agent, 2026-05-29): Diff touches 59 files (threshold: 30). CONTAMINATED — skipping rebase. Manual review required before rebasing.

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 13:39
@lusoris

lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by master after merge marathon 2026-05-31.

@lusoris lusoris closed this May 31, 2026
@lusoris
lusoris deleted the security/codeql-go-pvr-fixes-20260529 branch May 31, 2026 13:43
@lusoris
lusoris restored the security/codeql-go-pvr-fixes-20260529 branch May 31, 2026 18:44
@lusoris lusoris reopened this May 31, 2026
@lusoris
lusoris marked this pull request as draft May 31, 2026 18:50
@lusoris

lusoris commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #514 — bundled per bigger-PRs guidance.

@lusoris lusoris closed this Jun 1, 2026
lusoris added a commit that referenced this pull request Jun 2, 2026
… (ADR-0811)

- Extend .github/codeql-config.yml paths to cover the Phase 4 Go surface
  (cmd/, pkg/, api/) and exclude gen/go (generated protobuf stubs).
- Add codeql-go job to security-scans.yml covering vmafx-controller,
  vmafx-mcp, vmafx-node, and pkg/ai/infer.go with security-and-quality
  suite; SHA-pinned to the same codeql-action v4 already in use.
- Add ADR-0811 and changelog fragment documenting the Dependabot/Renovate
  posture (Renovate osvVulnerabilityAlerts is the operative mechanism).

Source: #171 (security/codeql-go-pvr-fixes-20260529).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 2, 2026
…eQL Go) (#514)

* chore(security): bump golang.org/x/net + x/sys to clear 7 govulncheck advisories

Cross-ecosystem dependency audit (pip-audit + govulncheck) on 2026-05-30
surfaced 7 Go advisories — 1 symbol-reachable (idna.ToASCII via the
operator healthz probe) and 6 module-level — on golang.org/x/net@v0.53.0
and golang.org/x/sys@v0.43.0. Bumped to v0.55.0 / v0.45.0 respectively
(x/term and x/text follow via minimum-version selection). govulncheck
re-run after the bump: clean. Python audit (4 requirements files + 6
pyproject manifests): clean. Container scan deferred — no
vmafx-dev-mcp:latest image locally.

See docs/research/dependency-audit-2026-05-30.md for the full audit
record.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(security): resolve CodeQL config conflict, add Go CodeQL coverage (ADR-0811)

- Extend .github/codeql-config.yml paths to cover the Phase 4 Go surface
  (cmd/, pkg/, api/) and exclude gen/go (generated protobuf stubs).
- Add codeql-go job to security-scans.yml covering vmafx-controller,
  vmafx-mcp, vmafx-node, and pkg/ai/infer.go with security-and-quality
  suite; SHA-pinned to the same codeql-action v4 already in use.
- Add ADR-0811 and changelog fragment documenting the Dependabot/Renovate
  posture (Renovate osvVulnerabilityAlerts is the operative mechanism).

Source: #171 (security/codeql-go-pvr-fixes-20260529).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
@lusoris
lusoris deleted the security/codeql-go-pvr-fixes-20260529 branch June 4, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant