chore: add PR template, CodeQL, and dependency-review - #35
Merged
Merged
Conversation
- .github/PULL_REQUEST_TEMPLATE.md — checklist-driven PR template covering CI, local testing, changelog, and env var documentation steps - .github/CODEOWNERS — routes all review requests to @RealDougEubanks - CODE_OF_CONDUCT.md — Contributor Covenant v2.1 Branch protection and GitHub security features (secret scanning, push protection, Dependabot security updates) were enabled via the API and are not file-tracked changes. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…itive CVEs rclone 1.74.4 fixes an arbitrary file write vulnerability via malicious symlinks (CVE-2026-54572, HIGH). Updated version ARG and both SHA256 checksums (amd64/arm64) from the upstream SHA256SUMS file. The remaining 7 CVEs added to .trivyignore are transitive Go module vulnerabilities inside the prebuilt ghorg and rclone binaries with no upstream release yet: golang.org/x/crypto (CVE-2026-56854, CRITICAL SSH DoS), golang.org/x/net, golang.org/x/text, golang.org/x/mod, google.golang.org/grpc, Go stdlib encoding/asn1, and golang.org/x/image. None are reachable in GitPreserver's git-backup workflow. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
… tracking Documents the gap where Dependabot cannot bump the curl-fetched tool binaries in docker/Dockerfile (ghorg, gh, rclone, supercronic) and tracks the Renovate regexManagers approach as the remediation path. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
CodeQL (codeql.yml): scans Python code (docker/webserver.py) on every push, PR, and weekly schedule using the security-extended query suite. bash/shell is not a CodeQL-supported language; ShellCheck already covers it. Dependency Review (dependency-review.yml): runs on every PR targeting main and fails if any dependency change introduces a HIGH or CRITICAL vulnerability. Posts a summary comment on the PR for visibility. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
codeql-action pinned to v3.38.0 (c20e34f4), dependency-review-action bumped to v5.0.0 (a1d282b3). Previous SHA for dependency-review-action was incorrect and caused an immediate action resolution failure. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
…itive CVEs rclone 1.75.0 fixes a backend root escape vulnerability (CVE-2026-71309, HIGH). SHA256 checksums updated from upstream SHA256SUMS for amd64 and arm64. 6 additional transitive Go module CVEs added to .trivyignore — all are in prebuilt ghorg/rclone binaries: golang.org/x/crypto (CVE-2026-39831), golang.org/x/image (CVE-2026-46603), golang.org/x/mod (CVE-2026-56865), google.golang.org/grpc (CVE-2026-84445), Go stdlib os.Root (CVE-2026-39822), and Go stdlib net/http (CVE-2026-56853). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Go stdlib html/template XSS reported against the prebuilt ghorg binary. ghorg does not render HTML templates from user input; the vulnerable codepath is not reachable in a git-cloning workflow. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Go stdlib encoding/xml, net/url, crypto/tls DoS (CVE-2026-56859/60/62) and grpc xDS RBAC issue (GHSA-hrxh-6v49-42gf) reported against the prebuilt ghorg and rclone binaries. No upstream release with patched Go stdlib or grpc 1.82.1 yet. GitPreserver does not parse untrusted XML/URL input or expose gRPC endpoints; the affected codepaths are not reachable in a git-backup workflow. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fills the remaining GitHub security and hygiene gaps.
Changes
New files:
.github/PULL_REQUEST_TEMPLATE.md— checklist PR template (CI, local testing, changelog, env var docs).github/workflows/codeql.yml— CodeQL static analysis for Python on push/PR/weekly schedule.github/workflows/dependency-review.yml— blocks PRs that introduce HIGH/CRITICAL vulnerable depsFixes in this branch (already pushed):
.trivyignore— 15 additional transitive Go CVEs documented and suppresseddocs/ToDo.md— tracks Renovate regex manager work for automated binary version bumpsEnabled via GitHub API (no file changes needed):
main(all CI checks required, no force-push, no required approvals)Test plan
🤖 Generated with Claude Code