Repository navigation
Fix expired preview snapshots and verify release onboarding - #7
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 69a8d59315
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| git -C /opt/advisory-db fetch --depth 1 origin "$ADVISORY_REV" && git -C /opt/advisory-db checkout --detach FETCH_HEAD && \ | ||
| test "$(git -C /opt/advisory-db rev-parse HEAD)" = "$ADVISORY_REV" && \ | ||
| python3 -c 'import json,subprocess; p="/opt/advisory-db"; g=lambda *a:subprocess.check_output(["git","-C",p,*a],text=True).strip(); json.dump({"revision":g("rev-parse","HEAD"),"commit_time":g("show","-s","--format=%cI","HEAD"),"source":"https://github.com/RustSec/advisory-db"},open("/opt/database.json","w"))' | ||
| python3 -c 'import json,subprocess; from datetime import datetime,timezone; p="/opt/advisory-db"; g=lambda *a:subprocess.check_output(["git","-C",p,*a],text=True).strip(); stamp=g("show","-s","--format=%cI","HEAD"); age=(datetime.now(timezone.utc)-datetime.fromisoformat(stamp)).total_seconds(); assert -86400 <= age <= 14*86400, "Advisory snapshot is stale or future-dated; choose a recent ADVISORY_REV"; json.dump({"revision":g("rev-parse","HEAD"),"commit_time":stamp,"source":"https://github.com/RustSec/advisory-db"},open("/opt/database.json","w"))' |
There was a problem hiding this comment.
Force the freshness check to bypass Docker's cache
When a previously built ADVISORY_REV later crosses the 14-day limit—for example, when the documented build helper is rerun before main advances—Docker can reuse this RUN layer because its inputs are unchanged, so the wall-clock assertion never executes. Docker documents that RUN cache is not invalidated automatically; consequently the helper can report success and retag the unchanged stale image, after which every scan still returns 503 from the worker's runtime check. Perform freshness validation outside the cached build layer or deliberately include an uncached time-dependent input.
Useful? React with 👍 / 👎.
| const response = await fetch('https://api.github.com/repos/RustSec/advisory-db/commits/main', { | ||
| headers: { Accept: 'application/vnd.github+json', 'User-Agent': 'rust-cve-sniffer' }, | ||
| signal: AbortSignal.timeout(15000), |
There was a problem hiding this comment.
Authenticate the CI revision lookup
When this helper runs in the new GitHub Actions job, the request has no authorization header because GITHUB_TOKEN is neither passed into the step environment nor read here. GitHub limits unauthenticated REST requests to 60 per hour per originating IP, so a hosted or self-hosted runner whose shared egress quota is exhausted receives 403 and fails the required web job before Docker starts, even though the workflow has a read token available. Pass the Actions token to the step and use it for this request, while retaining unauthenticated access for local builds.
Useful? React with 👍 / 👎.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
The Docker preview's default snapshot was dated September 9, outside its enforced 14-day limit. Resolve and pin an official RustSec revision during an explicit image build, reject expired snapshots at build time, and use that helper in the Windows launcher. CI now builds the actual worker, scans vulnerable/patched inputs, exercises API rejection paths, checks cleanup, and rejects the expired original snapshot.
Also fix the workspace verifier's null console summary by converting its ordered dictionary to PSCustomObject. Windows PowerShell 5.1 reproduced the old null output and confirmed the corrected summary against the completed workspace report.
Validation: all five jobs passed, including nine real Docker API cases, stale-snapshot rejection, Rust builds/tests on Ubuntu and Windows, the dependency audit and the Windows package checks. The dated record also covers actual Chrome/Edge downloads and clipboard use, a freshly downloaded v0.5.0 package, and desktop/runtime/enrichment/benchmark/workspace checks. A final documentation-only commit records those completed results.