Skip to content

fix: sec-check workflow permissions and fuzzing config - #6230

Closed
hivecommons-hive[bot] wants to merge 7 commits into
mainfrom
scanner/fix-6215
Closed

hivecommons-hive[bot] wants to merge 7 commits into
mainfrom
scanner/fix-6215

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Summary

Fixes three sec-check advisories in a single PR:

Closes #6215
Closes #6218
Closes #6223

Copilot AI review requested due to automatic review settings July 8, 2026 05:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot can't review bot-authored pull requests automatically. A user with Copilot access can request a review manually.

@kubestellar-prow kubestellar-prow Bot added the dco-signoff: yes Indicates the PR's author has signed the DCO. label Jul 8, 2026
@netlify

netlify Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for kubestellar-docs ready!

Name Link
🔨 Latest commit 756c21b
🔍 Latest deploy log https://app.netlify.com/projects/kubestellar-docs/deploys/6a4e35f0b6995a000818e919
😎 Deploy Preview https://deploy-preview-6230--kubestellar-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@kubestellar-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign clubanderson for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions github-actions Bot added copilot frontend ci-cd dependencies Pull requests that update a dependency file json yaml javascript and removed copilot labels Jul 8, 2026
@kubestellar-prow kubestellar-prow Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Jul 8, 2026
@kubestellar-prow

Copy link
Copy Markdown

Hi @kubestellar-hive[bot]. Thanks for your PR.

I'm waiting for a kubestellar member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubestellar-prow kubestellar-prow Bot added size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 8, 2026
@hivecommons-hive hivecommons-hive Bot changed the title [scanner] sec-check: workflow permissions + fuzzing config fix: sec-check workflow permissions and fuzzing config Jul 8, 2026
- technical-doc-writer.lock.yml: pin pre_activation job to contents:read +
  members:read (was inheriting workflow-level read-all without explicit block);
  narrow agent job from permissions:read-all to actions:read + contents:read +
  pull-requests:read (writes are only needed in safe_outputs/conclusion)
  Closes #6215

- sync-console-release-versions.yml: tighten workflow-level permissions from
  read-all to {} so any future job without an explicit block gets nothing by
  default; job-level contents:write + pull-requests:write unchanged
  Closes #6218

- create-version-branch.yml: add explanatory comment on permissions:{} intent
  (already minimal); no functional change
  Closes #6218

- Add .github/fuzzing/fuzz-mdx-sanitizer.ts: mutation-based fuzz harness for
  sanitizeHtmlForMdx() — checks that no <script>/<style> tags or event
  handlers survive after 20 000 mutated inputs
- Add .github/workflows/fuzz-mdx.yml: weekly scheduled CI run of the harness
  (also triggers on PRs touching the sanitizer)
  Closes #6223

Signed-off-by: kubestellar-hive[bot] <kubestellar-hive[bot]@users.noreply.github.com>
@kubestellar-prow kubestellar-prow Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. labels Jul 8, 2026
Fuzz testing revealed three bypass paths in sanitizeHtmlForMdx:
1. img alt/src/title values were output verbatim, allowing <script>/<style>
   to survive inside attribute values (fixed by applying escapeAngle).
2. Unclosed <script> opening tags (no matching </script>) were not removed
   by the balanced-pair stripUntilStable pass (fixed with a follow-up replace).
3. Same gap for unclosed <style> opening tags.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: kubestellar-hive[bot] <kubestellar-hive[bot]@users.noreply.github.com>
Comment thread src/lib/sanitizeHtml.ts Fixed
Comment thread src/lib/sanitizeHtml.ts Fixed
Replace single-pass .replace() on unclosed <style> and <script> opening
tags with stripUntilStable() to prevent multi-character bypass via
nested/interleaved input (e.g. <sc<script>ript>). Fixes CodeQL
CWE-116 alerts on lines 141 and 148 and the fuzz harness failure.

Signed-off-by: scanner <andan02@gmail.com>
Shantanu675 and others added 4 commits July 8, 2026 07:35
* Improve documentation homepage layout and content

Signed-off-by: Shantanu675 <shantanudanej05@gmail.com>

* Replace PanelLeftOpen button to improve UI

Signed-off-by: Shantanu675 <shantanudanej05@gmail.com>

---------

Signed-off-by: Shantanu675 <shantanudanej05@gmail.com>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Fixes #6218)

Signed-off-by: Scanner Bot <scanner-bot@kubestellar.io>
@kubestellar-prow kubestellar-prow Bot added dco-signoff: no Indicates the PR's author has not signed the DCO. and removed dco-signoff: yes Indicates the PR's author has signed the DCO. labels Jul 8, 2026
@kubestellar-prow

Copy link
Copy Markdown

Thanks for your pull request. Before we can look at it, you'll need to add a 'DCO signoff' to your commits.

📝 Please follow instructions in the contributing guide to update your commits with the DCO

Full details of the Developer Certificate of Origin can be found at developercertificate.org.

The list of commits missing DCO signoff:

  • 58836c8 chore: update leaderboard and contributor profile data
Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-cd copilot dco-signoff: yes Indicates the PR's author has signed the DCO. dependencies Pull requests that update a dependency file frontend javascript json needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. typescript yaml

Projects

None yet

5 participants