Skip to content

ci: run the cross-repo contract gate; clear two security findings - #17

Merged
evg-g merged 4 commits into
mainfrom
chore/pre-publish-cleanup
Oct 3, 2026
Merged

evg-g merged 4 commits into
mainfrom
chore/pre-publish-cleanup

Conversation

@evg-g

@evg-g evg-g commented Oct 3, 2026

Copy link
Copy Markdown
Owner

The cross-repo contract gate never ran

The contract job only ever ran the in-repo checksum guard: the device repo was never checked out, so check_telemetry_contract.py hit its missing-path guard and skipped the byte comparison against the source contract while still reporting success. Checks the device repo out alongside when DEVICE_REPO is set, and points the script at it.

CI now reports:

in-repo guard: vendored telemetry contract matches its recorded checksums.
cross-repo check: vendored telemetry contract matches the device source.

With the variable unset — a fork — the job keeps the checksum guard only and stays green, as before. The sibling lands inside the working tree, so it is ignored in git and Docker: this repo builds its image with COPY . ..

pytest 9.0.3 (PYSEC-2026-1845)

pip-audit reported PYSEC-2026-1845 / CVE-2025-71176 (CVSS 6.8) against pytest 8.4.2 — the predictable /tmp/pytest-of-{user} directory lets a local user cause a denial of service or escalate. Local vector only, and pytest never reaches the image, but it is a live advisory and the audit step reported it on every run.

The fix is in 9.0.3, across the major bound, which drags pytest-asyncio with it (0.24 pins pytest<9). The 1.x migration is a no-op here: the suite already runs asyncio_mode = "auto" and uses no event_loop fixture.

Verified on pytest 9.1.1 / pytest-asyncio 1.4.0 — 388 passing: 108 unit, 179 security + contract + property, 101 integration against real Postgres and Redis. pip-audit now reports no known vulnerabilities.

Full-history secret scan

On a pull request gitleaks scans only the pushed commits. On a full scan it surfaced the webhook fixture's signing secret in tests/integration/test_webhooks_api.py — the literal 0123456789abcdef, flagged by generic-api-key on entropy alone. Accepted by fingerprint in .gitleaksignore, with a note that the file is for reviewed false positives and never for a rotated secret. Verified over 66 commits: no leaks.

Also

docs/KNOWN_GAPS.md now opens its CI/CD section by stating that every gate not needing a cloud account runs on every PR, so it cannot be skim-read as "the pipeline is theatre".

Verification

Branch CI green, all 12 jobs.

🤖 Generated with Claude Code

evg-g and others added 4 commits October 3, 2026 13:37
The contract job only ever ran the in-repo checksum guard: the device repo
was never checked out, so check_telemetry_contract.py hit its missing-path
guard and skipped the byte comparison against the source contract while
still reporting success.

Check the device repo out alongside when the DEVICE_REPO variable is set,
and point the script at it. With the variable unset (a fork) the job keeps
the checksum guard only and stays green, as before.

The sibling lands inside the working tree, so ignore it in git and Docker:
this repo builds its image with COPY . ., which is how a signing key once
reached an image in the device repo.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The section listing what could not be executed locally opened straight
into the deploy limitations, so a skim-read came away thinking the
pipeline is theatre. Say first that every gate not needing a cloud account
runs on every PR. Also explain why the local seed login differs from the
browser demo's.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
On a pull request the gitleaks action scans only the pushed commits. On
workflow_dispatch -- and for anyone who clones and runs `gitleaks detect`
-- it scans the whole history, where one finding surfaces: the webhook
fixture's signing secret in tests/integration/test_webhooks_api.py, the
literal "0123456789abcdef". It signs nothing outside the test process and
is flagged by the generic-api-key rule on entropy alone.

Accept it by fingerprint in .gitleaksignore, with a note on why, so the
repo is clean under a full scan rather than clean only because of where
the scan looked. Verified: gitleaks 8.24.3 over 66 commits, no leaks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
pip-audit reports PYSEC-2026-1845 (CVE-2025-71176, CVSS 6.8) against
pytest 8.4.2: the predictable /tmp/pytest-of-{user} directory lets a local
user cause a denial of service or escalate. Local vector only, and pytest
is a dev dependency that never reaches the image, so the exposure is small
-- but it is a live advisory in a repo whose pitch is security scanning,
and the audit step reported it on every run.

The fix is in 9.0.3, across the major bound, which drags pytest-asyncio
with it: 0.24 pins pytest<9. The 1.x migration is a no-op here because the
suite already runs asyncio_mode="auto" and uses no event_loop fixture.

Verified on pytest 9.1.1 / pytest-asyncio 1.4.0: 108 unit, 179
security+contract+property, 101 integration against real Postgres and
Redis -- 388 passing, the full count the README quotes. pip-audit now
reports no known vulnerabilities.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@evg-g
evg-g merged commit df775f7 into main Oct 3, 2026
24 checks passed
@evg-g
evg-g deleted the chore/pre-publish-cleanup branch October 3, 2026 11:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant