Repository navigation
Conversation
Runs `sscsb init` on this repo for the first time (47 controls, 32 enabled) and fixes every real finding the first verify produced. Policy: strongest-tool-only. * Credential scanning is TruffleHog alone — `controls.secrets.gitleaks = false`. TruffleHog verifies a candidate against the issuing provider, so a finding is a live credential rather than a regex hit; gitleaks-action additionally needs a paid license for org-owned repositories. sscsb's secrets-scan.yml template emits the gitleaks job regardless of that key, so the job is removed by hand and must be removed again after any `sscsb init` re-run. * SAST is CodeQL + OpenGrep, both enabled. The archived semgrep/semgrep-action@v1 job in security.yml is retired; OpenGrep is Semgrep's open fork and resolves the same rulesets, so `p/rust` and `p/security-audit` were added to the OpenGrep run — same coverage, on a pinned cosign-verified binary, with SARIF uploaded to code scanning. Findings fixed: * CODEOWNERS was entirely inert. All ten rules named @grcengineering/security, a team that does not exist — GitHub's codeowners/errors endpoint returned "Unknown owner" for every line, so no rule bound to anyone and the code-owner-review path had nothing behind it. Rules now name @p4gs and cover the new .sscsb/ policy surface. * deny.toml could not be parsed by cargo-deny 0.19.4 at all: `unmaintained` became a scope rather than a severity in the v2 schema, and `vulnerability`, `unlicensed` and `copyleft` were removed. The `deny` job in security.yml — a required status check on main — could therefore never have run. Rewritten to the v2 schema with the same intent, and tightened: unmaintained = "all". * Two Renovate config files (pre-existing renovate.json plus the renovate.json5 sscsb wrote) make Renovate abort with "Found multiple config file names". Merged into renovate.json5; renovate.json deleted. * Dockerfile base images were tag-pinned, not digest-pinned. Both now carry sha256 digests (resolved 2026-09-12). * CodeQL analysed `actions` only, not this workspace's Rust. Added `rust` to the matrix with build-mode none. * release.yml and security.yml: harden-runner added to all ten jobs, persist-credentials: false on every checkout, --locked on cargo install. * security-insights.yml REPLACE-ME administrator filled in. Verify: 23 pass / 3 fail / 3 degraded before, 27 pass / 1 fail / 2 degraded after. Remaining: branch-protection (required signed commits is a repo-admin remote write, left for a human), signing-model (account-level attestations only the maintainer can truthfully make), scorecard (no published results until this lands on the default branch). AI-Assisted: true AI-Tool: Claude Code AI-Model: claude-opus-5 AI-Role: draft Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017N6Qc2T7buVAXHZ9vYa1xm
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
`sscsb scan --local` writes the checks that are only observable on a developer machine — which key git signs with, whether the installed hooks actually block, what is in the package-trust baseline, which scanners are on PATH — and signs the result in the `sscsb-scan-record` namespace with the repository's own committed trust anchor (.sscsb/policy/allowed_signers). A clone cannot observe any of it, so without this record the public directory scores those controls `unverified` and the repository reads provisional however good its posture is. Signed by the human-class signer this repo commits as approved (SHA256:prXatGO56nl8Or4JdDSzIIcj8hZE1jBxnFaXZOnAPDQ); ssh-keygen -Y verify returns Good for the namespace. Record asserts 28 pass / 1 fail / 1 degraded at 12094c5 — the residual FAIL is branch-protection's missing 'Require signed commits', a repo-admin remote write left for a human. Not submitted to the public directory: `sscsb scan --local --submit` is a separate, deliberate publication step. AI-Assisted: true AI-Tool: Claude Code AI-Model: claude-opus-5 AI-Role: draft Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017N6Qc2T7buVAXHZ9vYa1xm
Owner decision: run Gitleaks alongside TruffleHog rather than TruffleHog-only. Gitleaks catches generic and unverifiable secrets (e.g. a plausible api_key literal, or key formats with no provider-verification endpoint) that TruffleHog's --results=verified,unknown filter drops; independent probes confirmed this detection gap. CI runs the MIT-licensed gitleaks binary directly (pinned v8.30.1, checksum-verified before execution) since gitleaks-action requires a paid license for organization-owned repos. AI-Assisted: true AI-Tool: Claude Code AI-Model: Sonnet 5 AI-Role: draft Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012hwWMsTiv9Uf2gNbMh75uk
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update 2026-10-06: Gitleaks is kept alongside TruffleHog, by owner decision. TruffleHog only finds credentials for providers it has a detector for, and with
--results=verified,unknownit reports a match only when the provider confirms it live or the verification attempt errors; it drops matches it could not verify, including those from detectors that have no verifier. Gitleaks matches on shape, so it also catches generic secrets such as passwords, internal tokens and keys for services TruffleHog has no detector for. Restored in1f4133c.What
First-time
sscsb initbootstrap of this repository (47 controls, 32 enabled), plus a fix for every real finding the firstsscsb verifyproduced.sscsb verifybefore → after:23 pass / 3 fail / 3 degraded / 3 info(the first verify run aftersscsb init, before any fixes) →27 pass / 1 fail / 2 degraded / 2 info(at the original bootstrap commit12094c5, withcontrols.secrets.gitleaks = false; 15 controls deliberately disabled in both runs). Not re-run since Gitleaks was turned back on in1f4133c. The signed local scan record committed in10a0d73(.sscsb/scan-record.local.json+.sig) was also taken at12094c5and still listsgitleaks: disabled in config; it has not been regenerated or re-signed since1f4133c.Scanner choice per surface
controls.secrets.trufflehog = true,controls.secrets.gitleaks = true; Trivy viavuln-scan.yml'sscanners: vuln,secret,misconfig)--results=verified,unknownit reports a match only when the provider confirms it live or the verification attempt errors; it drops matches it could not verify, including those from detectors that have no verifier. Gitleaks matches on shape, so it also catches generic secrets such as passwords, internal tokens and keys for services TruffleHog has no detector for. Trivy's filesystem scan runs its own built-in secret-detection rules as a third, independent pass, outside the dedicatedsecrets-scan.ymljob. CI runs the MIT-licensed gitleaks binary directly (pinned v8.30.1, checksum-verified before execution), notgitleaks-action, since that action (non-OSS EULA since v2.0.0) refuses to scan org-owned repos without aGITLEAKS_LICENSEkey. The key itself is free from gitleaks.io, but none is configured for this org, and running the binary avoids both obtaining the key and the action's license-validation call.sscsb's
secrets-scan.ymltemplate emits agitleaks-actionjob. That job was dropped at bootstrap (12094c5) and replaced in1f4133cby a hand-written job that runs the pinned, checksum-verified gitleaks 8.30.1 binary over the PR/push commit range, with a hand-written.gitleaks.toml([extend] useDefault = true) as its ruleset.controls.secrets.gitleaks = truealso turns Gitleaks back on in the local sscsb pre-commit hook — which passes that same--config .gitleaks.toml— alongside TruffleHog, and in whatsscsb verifychecks for. The pre-push range scan never read this key: it runs Gitleaks whenever the binary is onPATH, passing no--configflag at all. Gitleaks itself defaults to<target path>/.gitleaks.tomlwhen--configis omitted, and the pre-push scan's target path is the repo root — so it already ran Gitleaks at12094c5(under gitleaks' built-in default ruleset, since no.gitleaks.tomlexisted in the repo yet) while the key wasfalse, and from1f4133con it picks up the same.gitleaks.tomlruleset as the CI job and pre-commit hook automatically, with nothing to wire up.The archived
semgrep/semgrep-action@v1job insecurity.ymlis retired. OpenGrep is Semgrep's open fork and resolves the same registry rulesets, sop/rustandp/security-auditwere added to the OpenGrep run: same rule coverage, now on a pinned cosign-verified binary with SARIF uploaded to code scanning. CI on1f4133c:Ran 19 rules on 63 files: 0 findings(SAST (OpenGrep) run 37414610635).Findings fixed
@grcengineering/security, a team that does not exist.GET /repos/grcengineering/cvm/codeowners/errorsreturnedUnknown ownerfor every line, so no rule bound to anyone — including the branch-protection "require review from Code Owners" path. Rules now name@p4gsand additionally cover the new.sscsb/policy surface. Swap back if a real, publicly-visible@grcengineering/securityteam with write access is ever created.deny.tomlcould not be parsed at all. cargo-deny 0.19.4:error[unexpected-value] ... unmaintained = "warn". The v2 schema turnedunmaintainedinto a scope, and removedvulnerability,unlicensed,copyleft. Thedenyjob — a required status check onmain— could therefore never have run. Rewritten to the v2 schema, same intent, and tightened (unmaintained = "all").cargo deny checknow exits 0.sscsb initwroterenovate.json5next to the pre-existingrenovate.json; Renovate aborts with "Found multiple config file names" when both exist. Merged intorenovate.json5(old cool-down rules preserved,isVulnerabilityAlertmigrated to the modernvulnerabilityAlertsblock);renovate.jsondeleted.cgr.dev/chainguard/rust:latest-devandcgr.dev/chainguard/static:latestnow carry sha256 digests (resolved 2026-09-12).actionsonly — not this workspace's Rust.rustadded to the matrix withbuild-mode: none.release.ymlandsecurity.ymlwere unhardened.harden-runneradded to all nine jobs,persist-credentials: falseon every checkout,--lockedoncargo install.security-insights.ymlREPLACE-MEadministrator placeholder filled in; reporting channel aligned withSECURITY.md.Left open, with reasons
branch-protection— FAIL.mainis missing Require signed commits; everything else already passes (required PRs, force-push block, required checks, deletion protection, stale-review dismissal, strict up-to-date).required_approving_review_countis0(checked 2026-10-06), so no reviewer-count gate applies here. This is a repo-admin remote write, deliberately not made by an agent.sscsb harden branch-protection --applyis not the fix here — it only edits rulesets, and this repo uses classic branch protection, so its plan output isno ruleset targets this branch — skipped. The one-line fix is:0; code-owner review; last-push approval) need a second reviewer and cannot be satisfied by a solo maintainer.signing-model— DEGRADED. Remaining items are account-level attestations only the maintainer can truthfully assert (github-webvigilant mode + phishing-resistant MFA, Codespaces GPG verification, Claude GitHub App authorization). Theagent-claude-codelane wants a distinct agent commit identity, which conflicts with this operator's standing one-signer directive — a policy call, not a config gap.scorecard— DEGRADED. No published Scorecard results yet;scorecard.ymlruns on push to the default branch, so this resolves once this PR lands.Merge note
maincurrently requires a PR but 0 approving reviews, withenforce_admins: true(checked 2026-10-06); PR #6 reportsmergeStateStatus: CLEAN/mergeable: MERGEABLE, so no reviewer or protection change is needed to merge it. Required signed commits are still missing (see branch-protection above), which remains a repo-admin action.AI-Assisted: true
AI-Tool: Claude Code
AI-Model: claude-opus-5
AI-Role: draft
🤖 Generated with Claude Code
https://claude.ai/code/session_017N6Qc2T7buVAXHZ9vYa1xm