Promote CI pipeline hardening to main (#470) - #471
Merged
Merged
Conversation
Contributor-controlled data (branch names, PR titles, provider directory
and service file names) reached /bin/sh via exec/os.system in the setup
and signing scripts, and symlinks under providers/src were dereferenced
by the update, sign and package steps of the post-merge build.
- setup-job.js / get-version.js: write REG_* via core.exportVariable,
parse the PR number with an anchored regex for GitHub merge and squash
subjects and require it to be numeric
- get-updated-providers.py: write PROVIDERS / NUM_PROVIDERS directly to
$GITHUB_ENV in heredoc form; accept only
providers/src/<provider>/<version>/{provider.yaml,services/<file>}
with every component matching [A-Za-z0-9_][A-Za-z0-9._-]*
- new scripts/common/provider_tree.py: shared name allowlist, symlink /
regular-file / containment checks, GITHUB_ENV writer, S3 key parser
- update-versions.py, sign-provider-docs.py: validate the provider tree
before reading it; shutil.copyfile instead of os.system("cp ...")
- simulate-REGISTRY-PULL.py: tarfile extractall with filter='data'
- pull-additional-docs-from-artifact-repo.py: validate artifact keys
before joining them onto local paths
- sign-file.sh, main.yml: quote arguments
- CONTRIBUTING.md: document the enforced layout and naming rules
All 38 existing providers (1909 files) pass the new checks unchanged.
Reported by Kevin Backhouse (GitHub Security Lab).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Harden registry CI pipeline against contributor-controlled names and symlinks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promotes #470 from
devtomain.Hardens the post-merge build pipeline against contributor-controlled input:
$GITHUB_ENVis written directly instead of through shellecho, provider directory and service file names are allowlisted, symlinks underproviders/srcare rejected before signing, and tar extraction usesfilter='data'. No provider content changes.Reported by Kevin Backhouse (GitHub Security Lab). Details, verification and reviewer notes are in #470.
🤖 Generated with Claude Code