Repository navigation
ci: run the cross-repo contract gate; clear two security findings - #17
Merged
Merged
Conversation
The contract job only ever ran the in-repo checksum guard: the device repo was never checked out, so check_telemetry_contract.py hit its missing-path guard and skipped the byte comparison against the source contract while still reporting success. Check the device repo out alongside when the DEVICE_REPO variable is set, and point the script at it. With the variable unset (a fork) the job keeps the checksum guard only and stays green, as before. The sibling lands inside the working tree, so ignore it in git and Docker: this repo builds its image with COPY . ., which is how a signing key once reached an image in the device repo. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The section listing what could not be executed locally opened straight into the deploy limitations, so a skim-read came away thinking the pipeline is theatre. Say first that every gate not needing a cloud account runs on every PR. Also explain why the local seed login differs from the browser demo's. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
On a pull request the gitleaks action scans only the pushed commits. On workflow_dispatch -- and for anyone who clones and runs `gitleaks detect` -- it scans the whole history, where one finding surfaces: the webhook fixture's signing secret in tests/integration/test_webhooks_api.py, the literal "0123456789abcdef". It signs nothing outside the test process and is flagged by the generic-api-key rule on entropy alone. Accept it by fingerprint in .gitleaksignore, with a note on why, so the repo is clean under a full scan rather than clean only because of where the scan looked. Verified: gitleaks 8.24.3 over 66 commits, no leaks. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
pip-audit reports PYSEC-2026-1845 (CVE-2025-71176, CVSS 6.8) against pytest 8.4.2: the predictable /tmp/pytest-of-{user} directory lets a local user cause a denial of service or escalate. Local vector only, and pytest is a dev dependency that never reaches the image, so the exposure is small -- but it is a live advisory in a repo whose pitch is security scanning, and the audit step reported it on every run. The fix is in 9.0.3, across the major bound, which drags pytest-asyncio with it: 0.24 pins pytest<9. The 1.x migration is a no-op here because the suite already runs asyncio_mode="auto" and uses no event_loop fixture. Verified on pytest 9.1.1 / pytest-asyncio 1.4.0: 108 unit, 179 security+contract+property, 101 integration against real Postgres and Redis -- 388 passing, the full count the README quotes. pip-audit now reports no known vulnerabilities. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The cross-repo contract gate never ran
The
contractjob only ever ran the in-repo checksum guard: the device repo was never checked out, socheck_telemetry_contract.pyhit its missing-path guard and skipped the byte comparison against the source contract while still reporting success. Checks the device repo out alongside whenDEVICE_REPOis set, and points the script at it.CI now reports:
With the variable unset — a fork — the job keeps the checksum guard only and stays green, as before. The sibling lands inside the working tree, so it is ignored in git and Docker: this repo builds its image with
COPY . ..pytest 9.0.3 (PYSEC-2026-1845)
pip-auditreported PYSEC-2026-1845 / CVE-2025-71176 (CVSS 6.8) against pytest 8.4.2 — the predictable/tmp/pytest-of-{user}directory lets a local user cause a denial of service or escalate. Local vector only, and pytest never reaches the image, but it is a live advisory and the audit step reported it on every run.The fix is in 9.0.3, across the major bound, which drags
pytest-asynciowith it (0.24 pinspytest<9). The 1.x migration is a no-op here: the suite already runsasyncio_mode = "auto"and uses noevent_loopfixture.Verified on pytest 9.1.1 / pytest-asyncio 1.4.0 — 388 passing: 108 unit, 179 security + contract + property, 101 integration against real Postgres and Redis.
pip-auditnow reports no known vulnerabilities.Full-history secret scan
On a pull request gitleaks scans only the pushed commits. On a full scan it surfaced the webhook fixture's signing secret in
tests/integration/test_webhooks_api.py— the literal0123456789abcdef, flagged bygeneric-api-keyon entropy alone. Accepted by fingerprint in.gitleaksignore, with a note that the file is for reviewed false positives and never for a rotated secret. Verified over 66 commits: no leaks.Also
docs/KNOWN_GAPS.mdnow opens its CI/CD section by stating that every gate not needing a cloud account runs on every PR, so it cannot be skim-read as "the pipeline is theatre".Verification
Branch CI green, all 12 jobs.
🤖 Generated with Claude Code