Skip to content

ci(dev2): keep migration workflow logs private; add encrypted read-only query - #262

Merged
ralyodio merged 1 commit into
masterfrom
ci/migrate-query
Sep 26, 2026
Merged

ralyodio merged 1 commit into
masterfrom
ci/migrate-query

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

What

This repo is public, and so are its Actions logs.

  1. inspect no longer lists the other Supabase stacks on dev2. The first version printed every Supabase container name and image on the box. Those runs are deleted. It now prints only the database that holds the ThreatCrush schema.
  2. New query mode. It runs the given SQL in a read-only session (PGOPTIONS=-c default_transaction_read_only=on). All psql output, errors included, goes to a file on the runner. What gets printed is that file encrypted with AES-256 under a fresh key, plus the key sealed to the RSA public key (pubkey input, base64 PEM) with OAEP-SHA256. Decrypt locally with the private key.

How verified

I ran the step bodies from the YAML locally against the local Supabase container, with ssh replaced by a local shell:

  • The query output decrypts correctly with the private key, and the marker string never appears in the log output.
  • CREATE TABLE is rejected with "cannot execute CREATE TABLE in a read-only transaction", and no table is created.
  • inspect prints only supabase_db_threatcrush.

actionlint is clean.

…ly query

This repo is public, so its Actions logs are too. inspect listed every
Supabase stack on dev2; it now prints only the ThreatCrush database. New
query mode runs SQL in a read-only session and prints only ciphertext: the
result is AES-encrypted with a fresh key sealed to an RSA public key the
caller supplies.
@ralyodio
ralyodio merged commit c53e542 into master Sep 26, 2026
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

16 finding(s)

HIGH/CRITICAL: 1 | MEDIUM: 7 | LOW: 8

Severity Rule Location
HIGH secret-aws-access-key prd/0003-detect-hardcoded-secrets-before-they-are-committed-or-served.md:126
MEDIUM sql-string-concatenation .github/workflows/migrate-dev2.yml:128
MEDIUM js-open-redirect apps/web/src/app/auth/login/page.tsx:67
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:104
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:108
MEDIUM js-open-redirect apps/web/src/components/funding/FundingClient.tsx:97
MEDIUM js-unescaped-html-sink apps/web/src/components/GuideReader.tsx:265
MEDIUM js-uninitialized-buffer packages/scan/src/node-rules.ts:456
LOW secret-generic-credential apps/web/src/app/api/auth/refresh/route.ts:17
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:26
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:27
LOW secret-generic-credential PRD.md:269
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:121
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:122
LOW sh-remote-script-execution scripts/smoke-test.sh:72
LOW secret-aws-access-key scripts/smoke-test.sh:150

Snippets are redacted; ThreatCrush never prints matched credential material.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant