Skip to content

fix(ci): sigstore signing audit — SBOM gaps + stale docs - #179

Closed
lusoris wants to merge 1 commit into
masterfrom
chore/sigstore-signing-audit-20260529
Closed

lusoris wants to merge 1 commit into
masterfrom
chore/sigstore-signing-audit-20260529

Conversation

@lusoris

@lusoris lusoris commented May 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Resolves an unresolved merge conflict marker left in docs/ai/security.md (layer-4 signing section)
  • Fixes stale claim that cosign emits .sig/.pem; workflow has used cosign v3 .bundle format since introduction
  • Expands the signing section in docs/development/release.md from a placeholder one-liner to full runnable examples (cosign verify-blob, cosign verify, cosign verify-attestation, slsa-verifier)
  • Adds missing attestations: write permission and syft install + SBOM + cosign attest steps to the build-rocm6, build-oneapi2026, and build-vulkan jobs in docker-publish-production.yml — these three GPU variants had signing but no SBOM attestation
  • Replaces the fragile pip install --quiet syft || true hack in the cuda12 job with the same anchore/sbom-action/download-syft step used by the cpu job
  • Adds missing syft install step to build-server (was calling syft without installing it)

Test plan

  • All pre-commit hooks pass (confirmed locally)
  • check yaml gate passes on the modified workflow file
  • Verify docs/ai/security.md has no conflict markers: grep -c '<<<<<<<' docs/ai/security.md returns 0
  • On next release tag push, confirm all six image variants (cpu, cuda12, rocm6, oneapi2026, vulkan, server) have cosign signatures AND SBOM attestations in GHCR

Deliverables checklist

  • Research digest — no digest needed: trivial doc + CI fix
  • Decision matrix — no alternatives: only-one-way fix
  • AGENTS.md invariant note — no rebase-sensitive invariants
  • Reproducer / smoke-test command — grep -c '<<<<<<<' docs/ai/security.md (should return 0 after this PR)
  • CHANGELOG fragment — changelog.d/security/sigstore-signing-audit.md
  • Rebase note — no rebase impact: doc and CI-workflow-only changes

🤖 Generated with Claude Code

@lusoris
lusoris enabled auto-merge (squash) May 29, 2026 10:25
@lusoris
lusoris disabled auto-merge May 29, 2026 11:43
@lusoris
lusoris marked this pull request as draft May 29, 2026 11:43
@lusoris
lusoris force-pushed the chore/sigstore-signing-audit-20260529 branch 2 times, most recently from 4e25335 to 3ae78a3 Compare May 29, 2026 13:37
- Fix stale claim that cosign emits .sig/.pem: supply-chain.yml uses cosign v3
  which emits a single .bundle file; update docs/ai/security.md accordingly
- Resolve committed merge conflict marker in docs/ai/security.md
- Expand docs/development/release.md Signing section from a placeholder
  one-liner to full cosign verify-blob, cosign verify, cosign
  verify-attestation, and slsa-verifier runnable examples
- Add attestations: write permission to build-rocm6, build-oneapi2026,
  and build-vulkan jobs (missing; cosign attest requires it)
- Add syft install + SBOM generate + cosign attest steps to build-rocm6,
  build-oneapi2026, and build-vulkan (cuda12 had it; these three did not)
- Replace pip install --quiet syft || true hack in cuda12 job with the
  same anchore/sbom-action/download-syft step used by the cpu job

no rebase impact: doc and CI-workflow-only changes

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris force-pushed the chore/sigstore-signing-audit-20260529 branch from 3ae78a3 to 382d82d Compare May 29, 2026 15:34
@lusoris
lusoris marked this pull request as ready for review May 31, 2026 13:38
@lusoris

lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by master after merge marathon 2026-05-31.

@lusoris lusoris closed this May 31, 2026
@lusoris
lusoris deleted the chore/sigstore-signing-audit-20260529 branch May 31, 2026 13:43
@lusoris
lusoris restored the chore/sigstore-signing-audit-20260529 branch May 31, 2026 18:43
@lusoris lusoris reopened this May 31, 2026
@lusoris
lusoris marked this pull request as draft May 31, 2026 18:50
@lusoris

lusoris commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #520 — bundled per 2026-06-01 triage.

@lusoris lusoris closed this Jun 1, 2026
@lusoris
lusoris deleted the chore/sigstore-signing-audit-20260529 branch June 4, 2026 08:09
lusoris added a commit that referenced this pull request Jun 12, 2026
…CI) (#868)

* fix(codeql): resolve HIGH-severity security-cpp-high alerts (23 sites)

- cpp/integer-multiplication-cast-to-long (11): pre-cast one operand to
  size_t / double / ptrdiff_t before int*int multiplications in
  cambi.c, float_vif.c (log message), iqa/convolve.c (img_offset),
  moment.c, psnr.c, and vif_tools.c (four memcpy size expressions).
  Add stddef.h to convolve.c for ptrdiff_t.

- cpp/incomplete-parity-check (3): change `% 2 == 1` to `% 2 != 0`
  in vif_tools.c (assert), svm.cpp (powi loop), pdjson.c (JSON
  object key/value alternation). The == 1 form is wrong for negative
  operands; != 0 is always correct.

- cpp/wrong-type-format-argument (2): fix float_vif.c error log that
  printed size_t fields scaled_w/scaled_h with %d; change to %zu.

- cpp/world-writable-file-creation (1): in vmaf.cpp replace bare
  fopen("wb") with open(O_WRONLY|O_CREAT|O_TRUNC, 0644)+fdopen() on
  POSIX so the created file is never world-writable independent of the
  caller's umask. Add <fcntl.h>.

- cpp/path-injection (4): in test_output.c resolve the mkstemp-created
  path through realpath() immediately after creation, breaking the taint
  chain from getenv("TMPDIR") to the vmaf_write_output call site.

- cpp/toctou-race-condition (2): skipped — both sites are in test
  cleanup (RMDIR after stat assertion). The stat result drives a test
  assertion, not a security-sensitive access decision; no atomic
  replacement of open() is applicable to rmdir. Reported as skipped.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(codeql): resolve security-python-and-ci CodeQL alerts

Fixes 18 open CodeQL alerts across the Python and CI categories:

- yaml.github-actions.security.run-shell-injection (#661): move
  github.event_name, github.base_ref, and github.event.before from
  inline ${{...}} interpolation to env: vars in the SYCL clang-tidy
  detect step of lint-and-format.yml.

- python.lang.security.use-defused-xml-parse (#216, #217): replace
  xml.etree.ElementTree with defusedxml.ElementTree in
  feature_extractor.py and quality_runner.py; add defusedxml>=0.7.1
  to python/pyproject.toml and python/requirements.txt.

- py/undefined-export (#352, #353, #354, #616): restructure
  aiutils/__init__.py to do a conditional eager import of the parquet
  helpers so the names are defined when pyarrow is present, and only
  include them in __all__ when the import succeeded.

- py/stack-trace-exposure (#178, #179, #585): log exception detail
  server-side and return a generic message to the HTTP client in
  http_transport.py _handle_score (invalid JSON, bad params, scorer
  error branches).

- python.lang.security.audit.dangerous-subprocess-use-tainted-env-args
  (#227, #372): add shlex.quote() around user-supplied path arguments
  passed into shell strings in extract_ugc_features.py and
  test_bbb_e2e_v5_bug_cluster.py.

- py/file-not-closed (#677, #678): replace bare open() calls with
  context managers in test_coverage_round3.py.

- py/redundant-comparison (#427, #431): remove redundant
  assert not (x != y) lines that duplicate the preceding assert x == y.

- py/equals-hash-mismatch (#182): convert RdPoint to frozen=True
  dataclass so __eq__ and __hash__ are generated consistently.

- py/inheritance/signature-mismatch (#197): add result_dict=None
  default to EnsembleVmafQualityRunner._populate_result_dict so the
  signature is compatible with the base class.

- py/multiple-definition (#201): drop redundant assignment to
  feature_found in feature_extractor.py wildcard discovery path.

- py/str-format/surplus-named-argument (#204): remove unused
  dataset= kwarg from the format() call in routine.py.

Skipped: python.lang.security.audit.insecure-file-permissions (#373) —
  the Unix socket at 0o660 is intentional (Go sidecar node must write
  to it and runs as the same UNIX group); tightening to 0o644 would
  break the IPC channel.

Skipped: py/path-injection (#180, #181) — _validate_path() already
  resolves the path and checks it against an allowlist before any file
  operation; the data flow is secure and the CodeQL dataflow trace is a
  false positive on this allowlisted pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant