chore(H2): baseline security gate #28
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!28
Loading…
Reference in a new issue
No description provided.
Delete branch "chore/h2-baseline-security"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Seeds the Area H baseline SCA + secret-scan gate. After merge, mark baseline-security a required status check.
AI review · advisory
Verdict: 3 things worth fixing (2 medium · 1 low).
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 6 distinct, 3 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Round 2 — cross-examination
GPT-OSS 120B#1Violation of baseline workflow immutability standard · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: —Gemma 4 31B#1Violation of canonical source restriction · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: —Devstral 2 123B#1Inconsistent comment in gitleaks step · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BDevstral 2 123B#3Unnecessary echo statements in gitleaks step · confirmed: — · refuted: Gemma 4 31BGemma 4 31B#2Missing shell safety flags · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: —Devstral 2 123B#2Redundant condition in gitleaks step · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BSynthesis — Devstral 2 123B wrote the final review from 3 confirmed findings (+3 unconfirmed).
Transcript
rv-20260812154356-f45f13— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260812154356-f45f13.@ -106,11 +106,28 @@ jobs:- name: SCA — Trivy filesystem (HIGH/CRITICAL gate).forgejo/workflows/baseline.yml:106· MEDIUM — Editing the seeded baseline workflow directlyThe PR modifies the seeded security workflow, which violates the agency standard that forbids editing the seeded copy. This can cause drift and break conformance audits.
panel tally 3/4 · reply here or use the finding board to agree/disagree
@ -110,2 +109,4 @@# Secret gate — the checkout is depth-1, so this scans the WHOLE TREE as of# the branch head (not just the diff). gitleaks reads ./.gitleaksignore# (fingerprints) by default. A hit here is already-burned → secret-rotation# runbook (ops/secret-rotation-runbook.md), not just a code edit..forgejo/workflows/baseline.yml:112· LOW — Redundant condition in gitleaks stepThe
if !condition is unnecessary because the--exit-code 1flag already handles failures.panel tally 3/4 · reply here or use the finding board to agree/disagree
.forgejo/workflows/baseline.yml:112· LOW — Redundant condition in gitleaks stepThe
if !condition is unnecessary because the--exit-code 1flag already handles failures.panel tally 3/4 · reply here or use the finding board to agree/disagree
@ -112,2 +113,2 @@- name: Secrets — gitleaks (full history)run: '$HOME/.local/bin/gitleaks detect --no-banner --redact --exit-code 1'# --verbose prints each finding (rule, file:line, fingerprint) with the# secret value redacted — without it a failure is an unactionableMEDIUM — Inconsistent comment in gitleaks step
The comment states 'scans full git history' but the checkout is depth-1, which contradicts the actual behavior.
panel tally 1/4 · reply here or use the finding board to agree/disagree
@ -114,0 +116,4 @@- name: Secrets — gitleaks (tree scan, redacted findings)run: |if ! "$HOME/.local/bin/gitleaks" detect --no-banner --redact --verbose --exit-code 1; thenechoLOW — Redundant condition in gitleaks step
The condition
if ! "$HOME/.local/bin/gitleaks" detect ...is redundant because the script already exits on failure.panel tally 1/4 · reply here or use the finding board to agree/disagree
@ -114,0 +117,4 @@run: |if ! "$HOME/.local/bin/gitleaks" detect --no-banner --redact --verbose --exit-code 1; thenechoecho "gitleaks failed — redacted findings above (rule, file:line, fingerprint)."LOW — Unnecessary echo statements in gitleaks step
The echo statements after the gitleaks command are redundant and do not add value to the error message.
panel tally 1/4 · reply here or use the finding board to agree/disagree
Merging despite the red gate, with justification: this PR changes only
.forgejo/workflows/baseline.yml(the gate itself). The failure is pre-existing on main since 2026-08-05 — everybaseline/trivy-fsrun on every commit has failed since (10 npm vulns: 9 HIGH + 1 CRITICAL@nuxt/devtoolsCVE-2026-71319). Becausebaselineis a required check and main itself is red, no PR can go green — including Renovate's own fix PRs #22/#23/#25/#26, which is a deadlock only an admin merge of the dep fixes can break. Those dep merges are left to the maintainer (feature branches #16/#17 are in flight). The gate version this PR installs prints the findings verbosely, which is how the backlog stays visible.