Skip to content

Improve pipeline security trust-boundary evidence#1139

Open
bozicovichsantiago20-oss wants to merge 1 commit into
UnitOneAI:mainfrom
bozicovichsantiago20-oss:codex/pipeline-provenance-gate
Open

Improve pipeline security trust-boundary evidence#1139
bozicovichsantiago20-oss wants to merge 1 commit into
UnitOneAI:mainfrom
bozicovichsantiago20-oss:codex/pipeline-provenance-gate

Conversation

@bozicovichsantiago20-oss
Copy link
Copy Markdown

Summary

  • Expands pipeline-security to review privileged workflow_run artifact handoffs, cache poisoning paths, and reusable workflow trust boundaries.
  • Adds explicit evidence states for repository/platform settings and cloud IAM/OIDC trust policies so the skill does not overclaim from YAML alone.
  • Adds vulnerable and benign fixtures for artifact poisoning, broad vs constrained OIDC trust, reusable workflow secrets: inherit, and trusted rebuild patterns.

Issue

Closes #1113

Bounty alignment

Skill improvement for skills/devsecops/pipeline-security. Target tier: Moderate ($100) if accepted by maintainers.

Validation

  • git diff --cached --check
  • Parsed the JSON IAM trust-policy fixtures successfully.
  • Checked required frontmatter markers and balanced Markdown code fences.
  • Checked all referenced external links; each returned HTTP 200.
  • Prompt-injection scan only matched the existing defensive Safety Notice text that tells the skill to treat hostile content as data.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] pipeline-security: workflow_run, OIDC trust policy, and cache-poisoning gaps

1 participant