Repository navigation
feat(scanner): bind plugin receipts to scan-policy provenance - #1167
Draft
seonghobae wants to merge 3 commits into
Draft
seonghobae wants to merge 3 commits into
seonghobae wants to merge 3 commits into
Conversation
Receipts record policy_provenance for the running AppGuardrail release and the exact scanner_policy_sha256 digest. Verification fails closed when the policy digest or scanner version disagrees. Relates to #1099.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
added a commit
that referenced
this pull request
Sep 7, 2026
Summary: - Snapshot 21:14 UTC records Draft #1167 `18bb1a0` stacked on #1166. - Receipt policy_provenance binds scanner release version and policy digest. - Verify fails closed when those disagree with the running scanner. Rationale: - #999 is the single writer of the product-technical gap baseline. - Noema/macos_utility_packs canaries are not this lane. Tests: - documentation-only; detector evidence lives on #1167 (2272/2272)
This was referenced Sep 7, 2026
seonghobae
added a commit
that referenced
this pull request
Sep 7, 2026
Summary: - Snapshot 22:05 UTC records Draft #1168 `4b9bcc6` stacked on #1167. - Receipt sbom_sha256 is a CycloneDX digest, not a second policy hash. - Malformed manifests stay empty-component SBOMs. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1168 (2301/2301)
Contributor
Author
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Successor of #1166 / issue #1099. Does not Close those. Bomb extract budget stays #1166. Does not steal #1165 setuid/world-writable or G-06 #1152.
Current exact authority
feat/claude-plugin-decompression-bomb-1099@0ef0f7d7f3c63faa822a8cff5a20e76514285da218bb1a0a87f912989ea3f3328cc7692fda1a9c0cdevelopUnique delta
Bind scan-policy provenance to the exact AppGuardrail release and the exact policy bytes used for the scan:
scanner_policy_sha256builder (SHA-256of detector policy bytes); do not add a second digest namepolicy_provenancerecordsschema_version,source_repositoryidentityContextualWisdomLab/appguardrail,scanner_release_versionfrom existing_SCANNER_VERSION(same as pyproject/__version__), and the samescanner_policy_sha256digestverify_plugin_scan_receiptfails closed when the policy digest orscanner_versiondisagrees with the running scanner, or whenpolicy_provenanceis swappedscan_result=passis not Noema admissionIntegration canaries (Noema / macos_utility_packs) are not this lane. No SPDX SBOM was generated.
Evidence
bba5b6athen GREEN18bb1a0claude_plugin_detector.pystatement coverage: 2272/2272 on Python 3.13claude_plugin_scan_cli.pystatement coverage: 91/91Relates to #1099. Relates to #1166.
Current non-force restack — 2026-09-12
This Draft is an ordinary two-parent descendant of prior head
18bb1a0a87f912989ea3f3328cc7692fda1a9c0cand current #1166 head348df03ac25d98d6c3ce31b9073f2428b06cd9e0. Exact head ise091853196297e0bb351752332c017a47525d579; exact tree isf6b0886f9b1b1ae16cc15947e37e1a5ef0920746. GitHub compare reports 3 ahead / 0 behind and preserves release/policy provenance with the current archive, mode, directive, command-rule, and MCP precision lineage. Exact-tree Claude-plugin tests are 317/317; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier exact-authority strings are historical evidence only.