Skip to content

feat(scanner): bind plugin receipts to scan-policy provenance - #1167

Draft
seonghobae wants to merge 3 commits into
feat/claude-plugin-decompression-bomb-1099from
feat/claude-plugin-policy-provenance-1099
Draft

seonghobae wants to merge 3 commits into
feat/claude-plugin-decompression-bomb-1099from
feat/claude-plugin-policy-provenance-1099

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Successor of #1166 / issue #1099. Does not Close those. Bomb extract budget stays #1166. Does not steal #1165 setuid/world-writable or G-06 #1152.

Current exact authority

Unique delta

Bind scan-policy provenance to the exact AppGuardrail release and the exact policy bytes used for the scan:

  • reuse the existing scanner_policy_sha256 builder (SHA-256 of detector policy bytes); do not add a second digest name
  • receipt policy_provenance records schema_version, source_repository identity ContextualWisdomLab/appguardrail, scanner_release_version from existing _SCANNER_VERSION (same as pyproject/__version__), and the same scanner_policy_sha256 digest
  • verify_plugin_scan_receipt fails closed when the policy digest or scanner_version disagrees with the running scanner, or when policy_provenance is swapped
  • identical source+policy still emit identical receipts
  • snippets/receipts omit secrets and bidi; scan_result=pass is not Noema admission

Integration canaries (Noema / macos_utility_packs) are not this lane. No SPDX SBOM was generated.

Evidence

  • RED bba5b6a then GREEN 18bb1a0
  • focused plugin tests: 287 passed
  • claude_plugin_detector.py statement coverage: 2272/2272 on Python 3.13
  • claude_plugin_scan_cli.py statement coverage: 91/91

Relates to #1099. Relates to #1166.

Current non-force restack — 2026-09-12

This Draft is an ordinary two-parent descendant of prior head 18bb1a0a87f912989ea3f3328cc7692fda1a9c0c and current #1166 head 348df03ac25d98d6c3ce31b9073f2428b06cd9e0. Exact head is e091853196297e0bb351752332c017a47525d579; exact tree is f6b0886f9b1b1ae16cc15947e37e1a5ef0920746. GitHub compare reports 3 ahead / 0 behind and preserves release/policy provenance with the current archive, mode, directive, command-rule, and MCP precision lineage. Exact-tree Claude-plugin tests are 317/317; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier exact-authority strings are historical evidence only.

RED: honest receipts must bind policy_provenance and fail closed when
scanner_version or the policy digest disagrees with the running scanner.
Relates to #1099. Does not Close #1099 or #1166.
Receipts record policy_provenance for the running AppGuardrail release
and the exact scanner_policy_sha256 digest. Verification fails closed
when the policy digest or scanner version disagrees. Relates to #1099.
@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 21:14 UTC records Draft #1167 `18bb1a0` stacked on #1166.
- Receipt policy_provenance binds scanner release version and policy digest.
- Verify fails closed when those disagree with the running scanner.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- Noema/macos_utility_packs canaries are not this lane.

Tests:
- documentation-only; detector evidence lives on #1167 (2272/2272)
seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 22:05 UTC records Draft #1168 `4b9bcc6` stacked on #1167.
- Receipt sbom_sha256 is a CycloneDX digest, not a second policy hash.
- Malformed manifests stay empty-component SBOMs.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- #1099 remaining surfaces stay on stacked successors, not Close.

Tests:
- documentation-only; detector evidence lives on #1168 (2301/2301)

Copy link
Copy Markdown
Contributor Author

Successor Draft #1168 (4b9bcc6) stacks unique CycloneDX sbom_sha256 on this head. Keep #1167 Draft. Do not Close.

@seonghobae seonghobae added enhancement New feature or request priority: medium Normal-priority or P2 work labels Sep 8, 2026 — with ChatGPT Codex Connector

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: medium Normal-priority or P2 work

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant