Skip to content

fix(ci): add tzdata, pyatr, nono-py to dep-confusion allowlist - #3033

Merged
Imran Siddique (imran-siddique) merged 2 commits into
mainfrom
fix/dep-confusion-scan-allowlist
Jun 15, 2026
Merged

Imran Siddique (imran-siddique) merged 2 commits into
mainfrom
fix/dep-confusion-scan-allowlist

Conversation

@imran-siddique

Copy link
Copy Markdown
Collaborator

Three PyPI packages flagged by dep-confusion-scan after recent merges to main.

Package Introduced by Reason
tzdata Pre-existing IANA timezone database; Windows tz support in agent-os
pyatr #3025 (ATR annotator example) AGT audit trail record library
nono-py #3029 (NonoSandboxProvider) OS-native Landlock/Seatbelt sandbox bindings

All three are real, registered PyPI packages. Adding them to REGISTERED_PACKAGES unblocks dep-confusion-scan on main.

No other changes.

All three are registered PyPI packages flagged after recent merges:
- tzdata: IANA tz database (Windows tz support in agent-os)
- pyatr: AGT audit trail record library (acs-atr-annotator example, PR #3025)
- nono-py: OS-native sandbox bindings (agt-sandbox[nono], PR #3029)

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: docs-sync-checker — Docs Sync

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Docs Sync

Documentation is in sync.

@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: security-scanner — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No security issues found.

@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: breaking-change-detector — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No breaking changes detected.

@github-actions github-actions Bot added the size/XS Extra small PR (< 10 lines) label Jun 15, 2026
@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: test-generator — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Test coverage looks good. No gaps identified.

@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 0 blockers, 1 warning. Changes are mostly safe but require a follow-up for enhanced security.

# Sev Issue Where
1 Warn Lack of automated validation for allowlist updates scripts/check_dependency_confusion.py

Action items: None.

Warnings:

# Description Resolution
1 Adding packages to the dependency confusion allowlist lacks automated validation to ensure they are legitimate and necessary. Fine as follow-up PRs.

@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@github-actions github-actions Bot added size/S Small PR (< 50 lines) and removed size/XS Extra small PR (< 10 lines) labels Jun 15, 2026
@imran-siddique
Imran Siddique (imran-siddique) merged commit 99a1ac9 into main Jun 15, 2026
125 of 127 checks passed
@imran-siddique
Imran Siddique (imran-siddique) deleted the fix/dep-confusion-scan-allowlist branch June 15, 2026 20:11
jlaportebot (jlaportebot) pushed a commit to jlaportebot/agent-governance-toolkit that referenced this pull request Jun 17, 2026
…soft#3033)

* fix(ci): add tzdata, pyatr, nono-py to dep-confusion allowlist

All three are registered PyPI packages flagged after recent merges:
- tzdata: IANA tz database (Windows tz support in agent-os)
- pyatr: AGT audit trail record library (acs-atr-annotator example, PR microsoft#3025)
- nono-py: OS-native sandbox bindings (agt-sandbox[nono], PR microsoft#3029)

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* fix(ci): add tzdata and pyatr to cspell allowlist

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/S Small PR (< 50 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant