Skip to content

fix(supply-chain): age-check =-pinned cargo dependencies - #3564

Merged
MohammadHaroonAbuomar merged 2 commits into
mainfrom
liamcrumm/supply-chain-exact-pin-age-check
Aug 1, 2026
Merged

MohammadHaroonAbuomar merged 2 commits into
mainfrom
liamcrumm/supply-chain-exact-pin-age-check

Conversation

@liamcrumm

Copy link
Copy Markdown
Contributor

Description

The 7-day cooling-off scanner skipped any cargo dependency written with the explicit exact-pin operator. =0.4.0-alpha.1 fails SAFE_VERSION_RE, which requires a leading alphanumeric character, so _resolve_cargo_deps dropped the dependency instead of age-checking it. Exact pinning is the form this repository's own version-selection guidance asks for, which left the rule blindest exactly where it was meant to be strictest.

The fix strips one leading =, plus any whitespace after it, before the safe-version check. == is not valid cargo syntax and still fails after a single strip.

The scanner change is authored by MohammadHaroonAbuomar. It is split out here because the Scanner trip-wire rejects any PR that touches scanner code and dependency manifests together, and asks for scanner updates to land first.

What the corrected scanner finds

Run against #3561, which retargets the policy engine onto published crates, it reported four things the previous version passed in silence:

Finding Detail
serde_yaml = "=0.9.34" 404s on crates.io. The release is published as 0.9.34+deprecated, and cargo ignores build metadata when matching, so the pin resolved locally while naming a version the registry does not have
agent-hooks-sdk 0.1.0-alpha.4 Published 1 day earlier, well inside the window
agent-control-spec 0.4.0-alpha.1 Published 6 days earlier
Two path dependencies Named versions that exist only in the working tree

The last row is worth a note for whoever tunes this next. A path dependency is never fetched from a registry, so its version requirement means nothing unless the depending crate is published. The scanner resolves it anyway. In #3561 that was resolved by dropping the requirement from crates marked publish = false, which is correct on its own terms, but a future change could skip path dependencies whose parent sets publish = false.

Tests

scripts/tests/test_check_release_age.py gains cases for the string, spaced, and inline-table = forms, the invalid == and bare = forms, candidate collection, and an end-to-end run where a too-young =-pinned crate fails the check. 57 tests pass.

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Maintenance (dependency updates, CI/CD, refactoring)
  • Security fix

Package(s) Affected

  • agent-os-kernel
  • agent-mesh
  • agent-runtime
  • agent-sre
  • agent-governance
  • docs / root

Repository tooling only: scripts/check_release_age.py and its tests. No dependency manifest is touched, so the Scanner trip-wire does not fire.

Checklist

  • My code follows the project style guidelines
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation

The scanner fix is MohammadHaroonAbuomar's work, carried here with authorship and sign-off intact. The follow-up commit only renames a test placeholder that the spell-check gate rejected.

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

Written with GitHub Copilot CLI.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

Related Issues

Unblocks #3561, which cannot go green while the scanner change and the dependency manifests share a branch.

MohammadHaroonAbuomar and others added 2 commits August 1, 2026 01:35
The cooling-off scanner silently dropped any Cargo dependency pinned
with the explicit exact-pin operator: `=0.4.0-alpha.1` fails
SAFE_VERSION_RE (which requires a leading alphanumeric), so
_resolve_cargo_deps skipped the dep instead of checking it. The two
crates this PR retargets onto — agent-control-spec 0.4.0-alpha.1 and
agent-hooks-sdk 0.1.0-alpha.4 — are both `=`-pinned and therefore
escaped the 7-day cooling-off rule entirely.

Strip a single leading `=` (with optional following whitespace) from
Cargo requirement strings before the safe-version check so exact pins
are resolved and age-checked like bare pins. `==` is not valid Cargo
syntax and still fails the safe-version check after one strip.

Tests cover the string, spaced, and inline-table `=` forms, the
invalid `==`/bare-`=` forms, candidate collection, and an end-to-end
run in which a too-young `=`-pinned crate fails the check.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
The spell-check gate rejects "newcrate". "new-crate" is an equally valid cargo
name and reads as two dictionary words.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 51d4e9b7-74f6-46f8-8b55-01be8d5eee05
Signed-off-by: Liam Crumm <liamcrumm@microsoft.com>
Copilot AI review requested due to automatic review settings August 1, 2026 01:37
@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions github-actions Bot added the tests label Aug 1, 2026
@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions github-actions Bot added the size/M Medium PR (< 200 lines) label Aug 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

TL;DR: 0 blockers, 0 warnings. No issues found. Clean change.

This PR fixes the release-age supply-chain scanner for Rust/Cargo manifests by ensuring dependencies pinned with Cargo’s explicit exact-pin operator (=1.2.3, including spaced and inline-table forms) are correctly normalized and included in the age-check candidate set, instead of being silently skipped.

Changes:

  • Normalize Cargo dependency versions by stripping a single leading = (and surrounding whitespace) before safe-version validation.
  • Add regression tests covering =-pinned Cargo deps across string, spaced, and inline-table forms, plus invalid == / bare = cases.
  • Add an end-to-end test verifying that a too-young =-pinned crate correctly fails the age gate.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
scripts/check_release_age.py Strips a single leading = from Cargo version pins so exact-pinned deps are age-checked rather than skipped.
scripts/tests/test_check_release_age.py Adds regression + end-to-end tests ensuring =-pinned Cargo deps are collected and enforced correctly.

liamcrumm added a commit that referenced this pull request Aug 1, 2026
The Scanner trip-wire rejects a PR that changes supply-chain scanner code and
dependency manifests together, and asks for the scanner update to land first.
The change is now #3564, with authorship
intact.

Every manifest problem it surfaced stays fixed here: the serde_yaml build
metadata pin, the agent-hooks-sdk cooling-off window, the meaningless version
requirements on path dependencies, and the core version.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 51d4e9b7-74f6-46f8-8b55-01be8d5eee05
Signed-off-by: Liam Crumm <liamcrumm@microsoft.com>

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The scanner change is the fix verified during the #3561 review: is_safe_version drops '='-pinned cargo requirements, so exact-pinned crates were silently skipped by the 7-day cooling-off gate; stripping the exact-pin operator restores age-checking (128 scripts tests pass, and running this scanner against #3561's branch resolves all 8 candidates instead of skipping the two new crates). Second commit is a test-only placeholder rename. Trip-wire green since this PR touches no dependency manifests.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar marked this pull request as ready for review August 1, 2026 02:39
@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit 93a7f44 into main Aug 1, 2026
137 checks passed
@MohammadHaroonAbuomar
MohammadHaroonAbuomar deleted the liamcrumm/supply-chain-exact-pin-age-check branch August 1, 2026 02:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/M Medium PR (< 200 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants