Repository navigation
Conversation
lusoris
force-pushed
the
security/codeql-go-pvr-fixes-20260529
branch
from
May 29, 2026 11:31
8b98726 to
b49d147
Compare
lusoris
marked this pull request as draft
May 29, 2026 11:48
…(ADR-0811) - Resolve unresolved git conflict markers in .github/codeql-config.yml left from the libvmaf/ -> core/ rename; adopt core/ layout in full. - Extend CodeQL paths to cover the Phase 4 Go surface (cmd/, pkg/, api/); exclude gen/go (generated protobuf stubs). - Add codeql-go job to security-scans.yml covering vmafx-controller, vmafx-mcp, vmafx-node, and pkg/ai/infer.go with security-and-quality suite; SHA-pinned to the same codeql-action v4 already in use. - Document Dependabot/Renovate posture: Renovate osvVulnerabilityAlerts is the operative alert mechanism (Dependabot superseded by ADR-0363). no rebase impact: CI-config-only change; no public API surface affected. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
force-pushed
the
security/codeql-go-pvr-fixes-20260529
branch
from
May 29, 2026 12:12
b49d147 to
b6dc61f
Compare
Contributor
Author
|
Pre-rebase check (batch agent, 2026-05-29): Diff touches 59 files (threshold: 30). CONTAMINATED — skipping rebase. Manual review required before rebasing. |
6 tasks done
lusoris
marked this pull request as ready for review
May 31, 2026 13:39
Contributor
Author
|
Superseded by master after merge marathon 2026-05-31. |
Contributor
Author
|
Superseded by #514 — bundled per bigger-PRs guidance. |
lusoris
added a commit
that referenced
this pull request
Jun 2, 2026
… (ADR-0811) - Extend .github/codeql-config.yml paths to cover the Phase 4 Go surface (cmd/, pkg/, api/) and exclude gen/go (generated protobuf stubs). - Add codeql-go job to security-scans.yml covering vmafx-controller, vmafx-mcp, vmafx-node, and pkg/ai/infer.go with security-and-quality suite; SHA-pinned to the same codeql-action v4 already in use. - Add ADR-0811 and changelog fragment documenting the Dependabot/Renovate posture (Renovate osvVulnerabilityAlerts is the operative mechanism). Source: #171 (security/codeql-go-pvr-fixes-20260529). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 2, 2026
…eQL Go) (#514) * chore(security): bump golang.org/x/net + x/sys to clear 7 govulncheck advisories Cross-ecosystem dependency audit (pip-audit + govulncheck) on 2026-05-30 surfaced 7 Go advisories — 1 symbol-reachable (idna.ToASCII via the operator healthz probe) and 6 module-level — on golang.org/x/net@v0.53.0 and golang.org/x/sys@v0.43.0. Bumped to v0.55.0 / v0.45.0 respectively (x/term and x/text follow via minimum-version selection). govulncheck re-run after the bump: clean. Python audit (4 requirements files + 6 pyproject manifests): clean. Container scan deferred — no vmafx-dev-mcp:latest image locally. See docs/research/dependency-audit-2026-05-30.md for the full audit record. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(security): resolve CodeQL config conflict, add Go CodeQL coverage (ADR-0811) - Extend .github/codeql-config.yml paths to cover the Phase 4 Go surface (cmd/, pkg/, api/) and exclude gen/go (generated protobuf stubs). - Add codeql-go job to security-scans.yml covering vmafx-controller, vmafx-mcp, vmafx-node, and pkg/ai/infer.go with security-and-quality suite; SHA-pinned to the same codeql-action v4 already in use. - Add ADR-0811 and changelog fragment documenting the Dependabot/Renovate posture (Renovate osvVulnerabilityAlerts is the operative mechanism). Source: #171 (security/codeql-go-pvr-fixes-20260529). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.github/codeql-config.ymlleft from thelibvmaf/ → core/rename (ADR-0700). The conflict caused all CodeQL jobs to consume a syntactically-broken config; GitHub CodeQL silently falls back to scanning everything when config is invalid.codeql-gojob tosecurity-scans.ymlcovering the Phase 4 Go surface (cmd/,pkg/,api/— vmafx-controller, vmafx-mcp, vmafx-node, pkg/ai/infer.go). SHA-pinned to the codeql-action v4 already in use; excludesgen/go(generated protobuf stubs).osvVulnerabilityAlerts: trueis the operative mechanism (Dependabot superseded by ADR-0363); no code change needed.Audit findings answered
SECURITY.md(root) with 72h ACK / 30-day fix SLA, GH private advisory URL, PGP email.dependabot.yml.disabledcorrectly superseded by Renovate (ADR-0363);osvVulnerabilityAlerts: trueinrenovate.json.scorecard.ymlruns weekly, publishes to dashboard, SHA-pinned atossf/scorecard-action@4eaacf0543.Deep-dive deliverables (ADR-0108)
## Alternatives consideredpython3 -c "import yaml; yaml.safe_load(open('.github/codeql-config.yml'))"— previously raised on conflict markers; now passeschangelog.d/security/0811-codeql-go-config-fix.mdTest plan
CodeQL (Go)job appears in Actions tab after mergeCodeQL (C/C++)andCodeQL (Python)jobs no longer show "invalid config" warningscheck yamlpre-commit passes (already verified locally in this commit)🤖 Generated with Claude Code