fix(supply-chain): exclude Docker build-context secrets - #295
fix(supply-chain): exclude Docker build-context secrets#295seonghobae wants to merge 10 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Protected-main synchronization completed without force push. Exact head: Local exact-head evidence:
The change remains limited to @codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Remove the duplicated Python support contract changes from this Docker security branch. PR #405 remains the single writer while this branch keeps its build-context credential exclusion delta. Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com> Commit-Message-Assisted-by: Claude (via Claude Code)
Closes #294.
Current authoritative boundary
Protected shipped truth is exact
main@3b38ead2d00f44eb578d0689087b9293b3dabe1e. This Draft remains the sole writer for.dockerignoreplus the focused Docker build-context security contract. Current exact head is1bd73dc4da2d48432cb93e681d6b299e66de0ff7onfix/docker-build-context-secrets-294; the previous body claim naming6e3d1722b5e44470d6b249cb4b1cbad8578f1396and older protected main as current is superseded by live GitHub metadata.This is next-release supply-chain/privacy hardening only. It adds no Docker runtime secret, network dependency, database, model/provider, transport, persistence, authorization, tenancy, credential-management, deployment or durable-audit authority.
Test-first lineage
Test-only RED
8ba8711dedcc2d85ee8fca451f53fd1fa16783a9reached exact checkout/install/typecheck and failed the new contract because protected.dockerignoredid not exclude.envor private-key material. Security Scan31653842335succeeded; SAST31653842248found a valid dynamic-RegExp defect in the initial test helper, which was repaired rather than suppressed.The repair recursively excludes local
.env*, npm/pnpm/yarn/Python registry credentials, netrc credentials and common PEM/KEY/PKCS#12 containers, with an ordered exception preserving deliberate.env.examplefiles. The deterministic contract proves required package, lock, source, style and demo inputs remain in the context. No lifecycle script or secret-mount behavior is introduced.Exact-current-head evidence
For unchanged exact head
1bd73dc4da2d48432cb93e681d6b299e66de0ff7against live protected main:32075062128: completed / success;32075062158: completed / success;32075062130: completed / success;COMMENTEDreview, not approval;Repository exact-head success is technical evidence only. Separately applicable central workflows and qualifying independent approval remain live authorities; predecessor/status/model evidence does not transfer.
Integration boundary
Keep Draft/unmerged while #118 owns the exact protected
v0.6.0publication/provenance boundary. Before any lifecycle transition refetch exact head/live base, rules/permissions, reviews/threads and every applicable repository/central workflow. Do not self-approve, weaken gates, transfer predecessor evidence, move protected main, or represent this active-PR repair as shipped.