Skip to content

Fix expired preview snapshots and verify release onboarding - #7

Merged
agammann merged 2 commits into
mainfrom
verify-release-onboarding
Oct 2, 2026
Merged

agammann merged 2 commits into
mainfrom
verify-release-onboarding

Conversation

@agammann

@agammann agammann commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

The Docker preview's default snapshot was dated September 9, outside its enforced 14-day limit. Resolve and pin an official RustSec revision during an explicit image build, reject expired snapshots at build time, and use that helper in the Windows launcher. CI now builds the actual worker, scans vulnerable/patched inputs, exercises API rejection paths, checks cleanup, and rejects the expired original snapshot.

Also fix the workspace verifier's null console summary by converting its ordered dictionary to PSCustomObject. Windows PowerShell 5.1 reproduced the old null output and confirmed the corrected summary against the completed workspace report.

Validation: all five jobs passed, including nine real Docker API cases, stale-snapshot rejection, Rust builds/tests on Ubuntu and Windows, the dependency audit and the Windows package checks. The dated record also covers actual Chrome/Edge downloads and clipboard use, a freshly downloaded v0.5.0 package, and desktop/runtime/enrichment/benchmark/workspace checks. A final documentation-only commit records those completed results.

@agammann
agammann marked this pull request as ready for review October 2, 2026 06:11

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 69a8d59315

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/Dockerfile.worker
git -C /opt/advisory-db fetch --depth 1 origin "$ADVISORY_REV" && git -C /opt/advisory-db checkout --detach FETCH_HEAD && \
test "$(git -C /opt/advisory-db rev-parse HEAD)" = "$ADVISORY_REV" && \
python3 -c 'import json,subprocess; p="/opt/advisory-db"; g=lambda *a:subprocess.check_output(["git","-C",p,*a],text=True).strip(); json.dump({"revision":g("rev-parse","HEAD"),"commit_time":g("show","-s","--format=%cI","HEAD"),"source":"https://github.com/RustSec/advisory-db"},open("/opt/database.json","w"))'
python3 -c 'import json,subprocess; from datetime import datetime,timezone; p="/opt/advisory-db"; g=lambda *a:subprocess.check_output(["git","-C",p,*a],text=True).strip(); stamp=g("show","-s","--format=%cI","HEAD"); age=(datetime.now(timezone.utc)-datetime.fromisoformat(stamp)).total_seconds(); assert -86400 <= age <= 14*86400, "Advisory snapshot is stale or future-dated; choose a recent ADVISORY_REV"; json.dump({"revision":g("rev-parse","HEAD"),"commit_time":stamp,"source":"https://github.com/RustSec/advisory-db"},open("/opt/database.json","w"))'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Force the freshness check to bypass Docker's cache

When a previously built ADVISORY_REV later crosses the 14-day limit—for example, when the documented build helper is rerun before main advances—Docker can reuse this RUN layer because its inputs are unchanged, so the wall-clock assertion never executes. Docker documents that RUN cache is not invalidated automatically; consequently the helper can report success and retag the unchanged stale image, after which every scan still returns 503 from the worker's runtime check. Perform freshness validation outside the cached build layer or deliberately include an uncached time-dependent input.

Useful? React with 👍 / 👎.

Comment thread web/build-worker.mjs
Comment on lines +7 to +9
const response = await fetch('https://api.github.com/repos/RustSec/advisory-db/commits/main', {
headers: { Accept: 'application/vnd.github+json', 'User-Agent': 'rust-cve-sniffer' },
signal: AbortSignal.timeout(15000),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Authenticate the CI revision lookup

When this helper runs in the new GitHub Actions job, the request has no authorization header because GITHUB_TOKEN is neither passed into the step environment nor read here. GitHub limits unauthenticated REST requests to 60 per hour per originating IP, so a hosted or self-hosted runner whose shared egress quota is exhausted receives 403 and fails the required web job before Docker starts, even though the workflow has a read token available. Pass the Actions token to the step and use it for this request, while retaining unauthenticated access for local builds.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T06:15:08.519754Z 69a8d59 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@agammann
agammann merged commit ec9c2cf into main Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant