* fix(ci): fork-safe compliance review via two-stage workflow_run Replaces the pull_request_target approach (which would run untrusted fork code with the AWS Bedrock secrets in env) with the GitHub-recommended split: - swedish-compliance-diff.yml (pull_request, no secrets, read-only token): computes the diff and uploads it as an artifact. Never runs project code. - swedish-compliance-review.yml (workflow_run, has secrets + write token): checks out ONLY the base repo (trusted script + skills), downloads the diff artifact, feeds it to the model as DATA, and posts the comment. Never checks out or executes fork PR code. scripts/swedish-compliance-review.mjs reads the diff from DIFF_FILE/FILES_FILE when set, with a fallback to git diff for same-repo runs. Safe alternative to #829. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(ci): pin workflow actions to commit SHAs (Superagent P1) Pin actions/checkout, setup-node, upload-artifact, download-artifact and the peter-evans comment actions to immutable 40-char SHAs with version comments, closing the two Superagent supply-chain findings. Matters most here since the review stage holds AWS Bedrock secrets + a write token. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(ci): full base fetch in compliance-diff so merge-base works when branch is behind The --depth=1 base fetch left git merge-base with no reachable common ancestor once main advanced past the PR branch, failing the prepare job under bash -e. checkout already uses fetch-depth: 0, so a full base fetch makes merge-base reliable regardless of how far base has moved. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(ci): harden compliance review per security audit Stage 1 (swedish-compliance-diff.yml): pass github.base_ref + PR number via env instead of interpolating ${{ }} into the run: shell (template-injection antipattern); add set -euo pipefail; printf over echo. Stage 2 (swedish-compliance-review.yml): pin @anthropic-ai/bedrock-sdk@0.31.0 and add --ignore-scripts — the privileged job (write token) must not run a floating @latest or dependency lifecycle scripts. set -euo pipefail on the PR-number guard. Script: frame the untrusted diff/files with a per-run unguessable random sentinel (not a code fence a hostile diff could close) plus an explicit 'treat as data, ignore embedded instructions' system-prompt guard and output constraints (no images/@-mentions/links/HTML). Legacy getDiff now uses execFileSync (argv array, no shell). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
52 lines
2.0 KiB
YAML
52 lines
2.0 KiB
YAML
name: Compliance diff
|
|
|
|
# Stage 1 of the fork-safe compliance review (see swedish-compliance-review.yml).
|
|
#
|
|
# This runs on the untrusted PR head, but is SAFE because it has NO secrets and
|
|
# only a read-only token: it computes the diff and uploads it as an artifact.
|
|
# It never runs project code (no `npm install`, no `node`) — only git plumbing,
|
|
# which does not execute repository hooks. The privileged half (model call +
|
|
# comment) lives in stage 2, which never checks out fork code.
|
|
|
|
on:
|
|
pull_request:
|
|
types: [opened, synchronize, reopened]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
prepare:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
with:
|
|
ref: ${{ github.event.pull_request.head.sha }}
|
|
fetch-depth: 0
|
|
- name: Compute diff vs base
|
|
# Pass GitHub context via env, never interpolate ${{ }} into the shell
|
|
# body — expression substitution happens before bash parses the script,
|
|
# so a value with shell metacharacters would be a code-execution sink.
|
|
env:
|
|
BASE_REF: ${{ github.base_ref }}
|
|
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
run: |
|
|
set -euo pipefail
|
|
# Full fetch (not --depth=1): the PR branch may be behind base, and a
|
|
# shallow base can leave merge-base with no reachable common ancestor.
|
|
# checkout above uses fetch-depth: 0, so HEAD already has full history.
|
|
git fetch origin "$BASE_REF"
|
|
MERGE_BASE=$(git merge-base "origin/$BASE_REF" HEAD)
|
|
git diff "$MERGE_BASE" HEAD > diff.patch
|
|
git diff --name-only "$MERGE_BASE" HEAD > files.txt
|
|
printf '%s\n' "$PR_NUMBER" > pr-number.txt
|
|
- name: Upload diff artifact
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
|
|
with:
|
|
name: compliance-input
|
|
path: |
|
|
diff.patch
|
|
files.txt
|
|
pr-number.txt
|
|
retention-days: 1
|