chore(H2): baseline security gate #12

Merged
tti-admin merged 2 commits from chore/h2-baseline-security into main 2026-07-22 21:54:15 +00:00
Owner

Seeds the Area H baseline SCA + secret-scan gate. After merge, mark baseline-security a required status check.

Seeds the Area H baseline SCA + secret-scan gate. After merge, mark baseline-security a required status check.
chore(H2): seed baseline security gate
Some checks failed
baseline-security / baseline (pull_request) Successful in 2m34s
baseline-security / baseline (push) Successful in 2m36s
scan / trivy-fs (push) Has been cancelled
scan / trivy-fs (pull_request) Has been cancelled
51134ba4c8
Merge branch 'main' into chore/h2-baseline-security
All checks were successful
baseline-security / baseline (push) Successful in 53s
scan / trivy-fs (push) Successful in 38s
ai-review / review (pull_request) Successful in 1m3s
baseline-security / baseline (pull_request) Successful in 50s
scan / trivy-fs (pull_request) Successful in 42s
c72ec1c349
Member

AI review · advisory

Verdict: 2 things worth fixing (1 medium · 1 low).

.forgejo/workflows/baseline.yml:82 · MEDIUM — editing a file that will be overwritten
The change modifies a seeded security gate directly in a repository, but the canonical source is security/baseline/baseline.yml in forgejo-stack. Local edits will be overwritten by the conformance audit.

Fix: Revert changes to .forgejo/workflows/baseline.yml and apply the version bumps to security/baseline/baseline.yml in the forgejo-stack repository instead.

.forgejo/workflows/baseline.yml:85 · LOW — checksums not updated in provenance docs
The SHA-256 hashes for the new Trivy and Gitleaks releases were updated here, but the corresponding provenance documentation was not updated, risking mismatched records used by audit scripts.

Fix: Update the SHA entries in ops/provenance/trivy.md and ops/provenance/gitleaks.md to match the new versions.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B — 2 raised, 2 confirmed, 0 refuted · web: not used · context: 1 files · 6 codebase · 4 standards chunks

Panel debate — how this review was reached

Grounding — context: 1 files · 6 codebase · 4 standards chunks

Round 1 — independent reviews

  • GPT-OSS 120B (1 finding, confidence 0.62): The version bump and checksum updates appear syntactically correct, but ensure provenance documentation is kept in sync.
  • Gemma 4 31B (1 finding, confidence 1.0): The PR updates scanner versions and checksums, but does so in a seeded file that is explicitly forbidden from being edited locally as it is managed by a central canonical source and audit script.
  • Devstral 2 123B (0 findings, confidence 0.95): The diff updates version pins and checksums for Trivy and Gitleaks, which is consistent with the codebase's supply-chain pinning practice and the agency's security standards.

Round 2 — cross-examination

  • GPT-OSS 120B#1 Checksums not updated in provenance docs · confirmed: Devstral 2 123B · refuted: Gemma 4 31B
  • Gemma 4 31B#1 Violation of canonical source constraint · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: —

Synthesis — Devstral 2 123B wrote the final review from 2 confirmed findings.

Transcript rv-20260722215008-8e38fc — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260722215008-8e38fc

Three superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.

### AI review · advisory **Verdict: 2 things worth fixing** (1 medium · 1 low). **`.forgejo/workflows/baseline.yml:82`** · MEDIUM — editing a file that will be overwritten The change modifies a seeded security gate directly in a repository, but the canonical source is `security/baseline/baseline.yml` in `forgejo-stack`. Local edits will be overwritten by the conformance audit. > **Fix:** Revert changes to `.forgejo/workflows/baseline.yml` and apply the version bumps to `security/baseline/baseline.yml` in the `forgejo-stack` repository instead. **`.forgejo/workflows/baseline.yml:85`** · LOW — checksums not updated in provenance docs The SHA-256 hashes for the new Trivy and Gitleaks releases were updated here, but the corresponding provenance documentation was not updated, risking mismatched records used by audit scripts. > **Fix:** Update the SHA entries in `ops/provenance/trivy.md` and `ops/provenance/gitleaks.md` to match the new versions. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B — 2 raised, 2 confirmed, 0 refuted · web: not used · context: 1 files · 6 codebase · 4 standards chunks</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 6 codebase · 4 standards chunks **Round 1 — independent reviews** - **GPT-OSS 120B** (1 finding, confidence 0.62): The version bump and checksum updates appear syntactically correct, but ensure provenance documentation is kept in sync. - **Gemma 4 31B** (1 finding, confidence 1.0): The PR updates scanner versions and checksums, but does so in a seeded file that is explicitly forbidden from being edited locally as it is managed by a central canonical source and audit script. - **Devstral 2 123B** (0 findings, confidence 0.95): The diff updates version pins and checksums for Trivy and Gitleaks, which is consistent with the codebase's supply-chain pinning practice and the agency's security standards. **Round 2 — cross-examination** - `GPT-OSS 120B#1` Checksums not updated in provenance docs · confirmed: Devstral 2 123B · refuted: Gemma 4 31B - `Gemma 4 31B#1` Violation of canonical source constraint · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: — **Synthesis** — Devstral 2 123B wrote the final review from 2 confirmed findings. <sub>Transcript `rv-20260722215008-8e38fc` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260722215008-8e38fc</sub> <sub>Three superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.</sub>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!12
No description provided.