Skip to content

security: enable and evidence private vulnerability reporting #73

Description

@seonghobae

Buyer-visible gap

Noema has protected private-first disclosure policy, a hardened read-only GitHub setting probe, and a protected scheduled/manual evidence workflow. The remaining commercial/security gap is a current protected-source retained audit receipt plus external reporter/staffing/end-to-end case proof. Repository source and CI must not fabricate those later evidence classes.

Current protected truth — 2026-08-25

Current protected main is GitHub-verified 2c83355529447248c246805d1954f268e027d2ab. The private-vulnerability-reporting implementation entered protected history through #423 as squash commit a7793751f5b033515e9d57ca276df4d77228ce64 and remains present on the current protected lineage; a779375... is integration history, not the current protected tip.

Current protected source contains:

  • root SECURITY.md with private-first reporting and content-free public fallback;
  • docs/security/vulnerability-handling.md with case roles/states, exact-source evidence, incident escalation, test-first remediation, independent review, bounded retention, legal hold and secure deletion/redaction semantics;
  • docs/security/private-vulnerability-reporting-audit.md;
  • hardened scripts/private-vulnerability-reporting-audit.mjs with repository/source binding, JSON/media/UTF-8/duplicate-key/size/timeout defenses and explicit enabled: true acceptance;
  • package command security:private-reporting-audit;
  • .github/workflows/private-vulnerability-reporting-audit.yml with manual dispatch plus daily schedule, contents: read only, credential-free exact checkout, no secret/write contract, and bounded artifact retention;
  • the workflow remains within the repository's reviewed immutable artifact-upload authority.

The historical #95 implementation line and merged #423 are integrated history, not current PR owners.

Live setting evidence already observed

On 2026-08-15 the repository status API returned { "enabled": true } for ContextualWisdomLab/noema, while repository visibility remained public. That is historical administrator-setting evidence for that observation time only. It does not prove that the setting is still enabled on 2026-08-25, external reporter UI visibility, notification delivery, staffing/backup coverage, case access, or a benign end-to-end disclosure exercise. Until a fresh protected-source audit is retained, do not promote the 2026-08-15 observation into current operational PASS.

#423 integration evidence

#423 was repaired after its first GREEN candidate exposed a real repository CI contract failure: the new artifact-producing workflow was absent from the complete reviewed upload-artifact workflow inventory. The canonical branch added that missing inventory entry, then non-destructively incorporated the then-current protected documentation tip. On unchanged exact head 76846a143e375d0f83305bb59e24bfc52d815ac5, Application CI 32092608629, reviewer-ci 32092608640, and central Security Scan 32092608636 all reached terminal success with zero unresolved review threads. #423 was then squash-merged as protected commit a7793751f5b033515e9d57ca276df4d77228ce64.

That proves historical source/workflow integration only. It does not prove a current protected audit execution, reporter/staffing/case evidence, release/deployment, or acquisition readiness.

Acceptance criteria

Repository-owned setting evidence

  • Private-first policy, vulnerability lifecycle, read-only setting probe and adversarial response handling are protected source.
  • Administrator setting was observed enabled on 2026-08-15; preserve it as dated historical evidence only.
  • security(operations): retain private-reporting setting evidence #423 reached terminal-success exact-head CI/reviewer/Security evidence with zero valid unresolved findings before integration.
  • Integrate the unchanged security(operations): retain private-reporting setting evidence #423 semantics under protected governance.
  • Run the protected-source private-vulnerability-reporting audit against the then-current exact protected main and retain a report bound to exact repository, exact protected source revision, observation timestamp and immutable workflow/run identity.
  • A failing/unavailable/stale audit remains FAIL/non-authoritative; no retained report is edited into PASS.

External reporter evidence

  • From an unauthenticated or ordinary external-reporter perspective, verify GitHub exposes Report a vulnerability for the intended public repository without exposing technical details publicly.
  • Retain bounded observation evidence that does not contain a real vulnerability, reporter identity, secret, exploit payload or unnecessary PII.

Staffing / benign exercise evidence

  • At least two authorized maintainers or the approved security team can access private reports; record primary/backup ownership without publishing sensitive identity data unnecessarily.
  • A benign synthetic report or draft advisory exercises receipt, acknowledgement, assignment, private technical handling, duplicate behavior where applicable, independent review, and closure.
  • Observe notification delivery and backup ownership rather than infer them from configuration prose.
  • Prove no vulnerability details enter public issues/PRs/CI/model prompts/public artifacts.
  • Exercise the disabled/unavailable fallback using only the content-free Private security contact requested path before technical details move to an approved private case.

Buyer / transfer evidence

Current execution boundary

The repository-owned source/workflow gap is integrated. The currently available GitHub write surface does not expose a fresh generic workflow_dispatch operation for this audit workflow, so an immediate protected audit run must not be fabricated through a rerun, status edit, or alternate source path. The scheduled workflow remains the legitimate future evidence path. Waiting blocks only this operational sub-lane.

Non-goals / guardrails

No public vulnerability details, synthetic setting claims, invented security email/PGP/bounty/SLA/24x7 staffing, PAT/App credential merely for a public status GET, self-modifying workflow, protection bypass, synthetic approval, or release because historical setting/source evidence was green.

Related: #5, #27, #29, #40, #66, #227, #407.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: accessibilityAccessibility and assistive-technology supportarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: highHigh-priority or P1 workscope: product-gapCustomer-visible product gapstatus: triagedOpen issue has an organization taxonomy assignmenttype: securitySecurity vulnerability or security-specific remediation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions