Repository navigation
fix(supply-chain): age-check =-pinned cargo dependencies - #3564
Conversation
The cooling-off scanner silently dropped any Cargo dependency pinned with the explicit exact-pin operator: `=0.4.0-alpha.1` fails SAFE_VERSION_RE (which requires a leading alphanumeric), so _resolve_cargo_deps skipped the dep instead of checking it. The two crates this PR retargets onto — agent-control-spec 0.4.0-alpha.1 and agent-hooks-sdk 0.1.0-alpha.4 — are both `=`-pinned and therefore escaped the 7-day cooling-off rule entirely. Strip a single leading `=` (with optional following whitespace) from Cargo requirement strings before the safe-version check so exact pins are resolved and age-checked like bare pins. `==` is not valid Cargo syntax and still fails the safe-version check after one strip. Tests cover the string, spaced, and inline-table `=` forms, the invalid `==`/bare-`=` forms, candidate collection, and an end-to-end run in which a too-young `=`-pinned crate fails the check. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
The spell-check gate rejects "newcrate". "new-crate" is an equally valid cargo name and reads as two dictionary words. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 51d4e9b7-74f6-46f8-8b55-01be8d5eee05 Signed-off-by: Liam Crumm <liamcrumm@microsoft.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
There was a problem hiding this comment.
Pull request overview
TL;DR: 0 blockers, 0 warnings. No issues found. Clean change.
This PR fixes the release-age supply-chain scanner for Rust/Cargo manifests by ensuring dependencies pinned with Cargo’s explicit exact-pin operator (=1.2.3, including spaced and inline-table forms) are correctly normalized and included in the age-check candidate set, instead of being silently skipped.
Changes:
- Normalize Cargo dependency versions by stripping a single leading
=(and surrounding whitespace) before safe-version validation. - Add regression tests covering
=-pinned Cargo deps across string, spaced, and inline-table forms, plus invalid==/ bare=cases. - Add an end-to-end test verifying that a too-young
=-pinned crate correctly fails the age gate.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
scripts/check_release_age.py |
Strips a single leading = from Cargo version pins so exact-pinned deps are age-checked rather than skipped. |
scripts/tests/test_check_release_age.py |
Adds regression + end-to-end tests ensuring =-pinned Cargo deps are collected and enforced correctly. |
The Scanner trip-wire rejects a PR that changes supply-chain scanner code and dependency manifests together, and asks for the scanner update to land first. The change is now #3564, with authorship intact. Every manifest problem it surfaced stays fixed here: the serde_yaml build metadata pin, the agent-hooks-sdk cooling-off window, the meaningless version requirements on path dependencies, and the core version. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 51d4e9b7-74f6-46f8-8b55-01be8d5eee05 Signed-off-by: Liam Crumm <liamcrumm@microsoft.com>
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
The scanner change is the fix verified during the #3561 review: is_safe_version drops '='-pinned cargo requirements, so exact-pinned crates were silently skipped by the 7-day cooling-off gate; stripping the exact-pin operator restores age-checking (128 scripts tests pass, and running this scanner against #3561's branch resolves all 8 candidates instead of skipping the two new crates). Second commit is a test-only placeholder rename. Trip-wire green since this PR touches no dependency manifests.
Description
The 7-day cooling-off scanner skipped any cargo dependency written with the explicit exact-pin operator.
=0.4.0-alpha.1failsSAFE_VERSION_RE, which requires a leading alphanumeric character, so_resolve_cargo_depsdropped the dependency instead of age-checking it. Exact pinning is the form this repository's own version-selection guidance asks for, which left the rule blindest exactly where it was meant to be strictest.The fix strips one leading
=, plus any whitespace after it, before the safe-version check.==is not valid cargo syntax and still fails after a single strip.The scanner change is authored by MohammadHaroonAbuomar. It is split out here because the Scanner trip-wire rejects any PR that touches scanner code and dependency manifests together, and asks for scanner updates to land first.
What the corrected scanner finds
Run against #3561, which retargets the policy engine onto published crates, it reported four things the previous version passed in silence:
serde_yaml = "=0.9.34"0.9.34+deprecated, and cargo ignores build metadata when matching, so the pin resolved locally while naming a version the registry does not haveagent-hooks-sdk 0.1.0-alpha.4agent-control-spec 0.4.0-alpha.1The last row is worth a note for whoever tunes this next. A
pathdependency is never fetched from a registry, so its version requirement means nothing unless the depending crate is published. The scanner resolves it anyway. In #3561 that was resolved by dropping the requirement from crates markedpublish = false, which is correct on its own terms, but a future change could skip path dependencies whose parent setspublish = false.Tests
scripts/tests/test_check_release_age.pygains cases for the string, spaced, and inline-table=forms, the invalid==and bare=forms, candidate collection, and an end-to-end run where a too-young=-pinned crate fails the check. 57 tests pass.Type of Change
Package(s) Affected
Repository tooling only:
scripts/check_release_age.pyand its tests. No dependency manifest is touched, so the Scanner trip-wire does not fire.Checklist
Attribution & Prior Art
The scanner fix is MohammadHaroonAbuomar's work, carried here with authorship and sign-off intact. The follow-up commit only renames a test placeholder that the spell-check gate rejected.
AI Assistance
Written with GitHub Copilot CLI.
IP, Patents, and Licensing
Related Issues
Unblocks #3561, which cannot go green while the scanner change and the dependency manifests share a branch.