chore(H2): baseline security gate #28

Merged
A-Guevara merged 1 commit from chore/h2-baseline-security into main 2026-08-12 15:46:27 +00:00
Owner

Seeds the Area H baseline SCA + secret-scan gate. After merge, mark baseline-security a required status check.

Seeds the Area H baseline SCA + secret-scan gate. After merge, mark baseline-security a required status check.
chore(H2): seed baseline security gate
Some checks failed
baseline-security / baseline (push) Failing after 2m40s
scan / trivy-fs (push) Failing after 1m3s
baseline-security / baseline (pull_request) Failing after 1m9s
scan / trivy-fs (pull_request) Failing after 1m0s
ai-review / review (pull_request) Successful in 2m56s
de3d7e0cee
ai-review-bot left a comment

AI review · advisory

Verdict: 3 things worth fixing (2 medium · 1 low).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 6 distinct, 3 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (1 finding, confidence 0.97): The change edits the seeded baseline security workflow, which is prohibited by the agency standard; revert this edit and implement any custom logic elsewhere.
  • Gemma 4 31B (2 findings, confidence 1.0): The PR implements useful verbosity for gitleaks failures, but it violates a critical architectural constraint by editing a seeded file that is managed by an external canonical source and a conformance
  • Devstral 2 123B (3 findings, confidence 0.85): The changes in the PR diff are mostly fine, but there are a few inconsistencies and redundancies that should be addressed.
  • Laguna S 2.1 (0 findings, confidence 0.82): The diff is locally sound — switching gitleaks to a depth-1 tree scan with --redact --verbose, plus actionable failure messaging — but it contradicts the seeded canonical baseline at [standard] tti/co

Round 2 — cross-examination

  • GPT-OSS 120B#1 Violation of baseline workflow immutability standard · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: —
  • Gemma 4 31B#1 Violation of canonical source restriction · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: —
  • Devstral 2 123B#1 Inconsistent comment in gitleaks step · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B
  • Devstral 2 123B#3 Unnecessary echo statements in gitleaks step · confirmed: — · refuted: Gemma 4 31B
  • Gemma 4 31B#2 Missing shell safety flags · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: —
  • Devstral 2 123B#2 Redundant condition in gitleaks step · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B

Synthesis — Devstral 2 123B wrote the final review from 3 confirmed findings (+3 unconfirmed).

Transcript rv-20260812154356-f45f13 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260812154356-f45f13.

### AI review · advisory **Verdict: 3 things worth fixing** (2 medium · 1 low). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 6 distinct, 3 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (1 finding, confidence 0.97): The change edits the seeded baseline security workflow, which is prohibited by the agency standard; revert this edit and implement any custom logic elsewhere. - **Gemma 4 31B** (2 findings, confidence 1.0): The PR implements useful verbosity for gitleaks failures, but it violates a critical architectural constraint by editing a seeded file that is managed by an external canonical source and a conformance - **Devstral 2 123B** (3 findings, confidence 0.85): The changes in the PR diff are mostly fine, but there are a few inconsistencies and redundancies that should be addressed. - **Laguna S 2.1** (0 findings, confidence 0.82): The diff is locally sound — switching gitleaks to a depth-1 tree scan with --redact --verbose, plus actionable failure messaging — but it contradicts the seeded canonical baseline at [standard] tti/co **Round 2 — cross-examination** - `GPT-OSS 120B#1` Violation of baseline workflow immutability standard · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: — - `Gemma 4 31B#1` Violation of canonical source restriction · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: — - `Devstral 2 123B#1` Inconsistent comment in gitleaks step · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B - `Devstral 2 123B#3` Unnecessary echo statements in gitleaks step · confirmed: — · refuted: Gemma 4 31B - `Gemma 4 31B#2` Missing shell safety flags · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: — - `Devstral 2 123B#2` Redundant condition in gitleaks step · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B **Synthesis** — Devstral 2 123B wrote the final review from 3 confirmed findings (+3 unconfirmed). <sub>Transcript `rv-20260812154356-f45f13` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260812154356-f45f13`.</sub>
@ -106,11 +106,28 @@ jobs:
- name: SCA — Trivy filesystem (HIGH/CRITICAL gate)
Member

.forgejo/workflows/baseline.yml:106 · MEDIUM — Editing the seeded baseline workflow directly
The PR modifies the seeded security workflow, which violates the agency standard that forbids editing the seeded copy. This can cause drift and break conformance audits.

Fix: Revert changes to .forgejo/workflows/baseline.yml and apply the logic to security/baseline/baseline.yml in the forgejo-stack repository instead.

panel tally 3/4 · reply here or use the finding board to agree/disagree

**`.forgejo/workflows/baseline.yml:106`** · MEDIUM — Editing the seeded baseline workflow directly The PR modifies the seeded security workflow, which violates the agency standard that forbids editing the seeded copy. This can cause drift and break conformance audits. > **Fix:** Revert changes to `.forgejo/workflows/baseline.yml` and apply the logic to `security/baseline/baseline.yml` in the forgejo-stack repository instead. <sub>panel tally 3/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812154356-f45f13:GPT-OSS 120B#1 -->
@ -110,2 +109,4 @@
# Secret gate — the checkout is depth-1, so this scans the WHOLE TREE as of
# the branch head (not just the diff). gitleaks reads ./.gitleaksignore
# (fingerprints) by default. A hit here is already-burned → secret-rotation
# runbook (ops/secret-rotation-runbook.md), not just a code edit.
Member

.forgejo/workflows/baseline.yml:112 · LOW — Redundant condition in gitleaks step
The if ! condition is unnecessary because the --exit-code 1 flag already handles failures.

Fix: Remove the if condition and run the command directly.

panel tally 3/4 · reply here or use the finding board to agree/disagree

**`.forgejo/workflows/baseline.yml:112`** · LOW — Redundant condition in gitleaks step The `if !` condition is unnecessary because the `--exit-code 1` flag already handles failures. > **Fix:** Remove the `if` condition and run the command directly. <sub>panel tally 3/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812154356-f45f13:Gemma 4 31B#1 -->
Member

.forgejo/workflows/baseline.yml:112 · LOW — Redundant condition in gitleaks step
The if ! condition is unnecessary because the --exit-code 1 flag already handles failures.

Fix: Remove the if condition and run the command directly.

panel tally 3/4 · reply here or use the finding board to agree/disagree

**`.forgejo/workflows/baseline.yml:112`** · LOW — Redundant condition in gitleaks step The `if !` condition is unnecessary because the `--exit-code 1` flag already handles failures. > **Fix:** Remove the `if` condition and run the command directly. <sub>panel tally 3/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812154356-f45f13:Gemma 4 31B#2 -->
@ -112,2 +113,2 @@
- name: Secrets — gitleaks (full history)
run: '$HOME/.local/bin/gitleaks detect --no-banner --redact --exit-code 1'
# --verbose prints each finding (rule, file:line, fingerprint) with the
# secret value redacted — without it a failure is an unactionable
Member

MEDIUM — Inconsistent comment in gitleaks step

The comment states 'scans full git history' but the checkout is depth-1, which contradicts the actual behavior.

Fix: Update the comment to accurately reflect that the scan covers the whole tree at the branch head due to depth-1 checkout.

panel tally 1/4 · reply here or use the finding board to agree/disagree

**MEDIUM** — Inconsistent comment in gitleaks step The comment states 'scans full git history' but the checkout is depth-1, which contradicts the actual behavior. > **Fix:** Update the comment to accurately reflect that the scan covers the whole tree at the branch head due to depth-1 checkout. <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812154356-f45f13:Devstral 2 123B#1 -->
@ -114,0 +116,4 @@
- name: Secrets — gitleaks (tree scan, redacted findings)
run: |
if ! "$HOME/.local/bin/gitleaks" detect --no-banner --redact --verbose --exit-code 1; then
echo
Member

LOW — Redundant condition in gitleaks step

The condition if ! "$HOME/.local/bin/gitleaks" detect ... is redundant because the script already exits on failure.

Fix: Remove the if condition and directly run the command, as the --exit-code 1 flag will handle failures appropriately.

panel tally 1/4 · reply here or use the finding board to agree/disagree

**LOW** — Redundant condition in gitleaks step The condition `if ! "$HOME/.local/bin/gitleaks" detect ...` is redundant because the script already exits on failure. > **Fix:** Remove the `if` condition and directly run the command, as the `--exit-code 1` flag will handle failures appropriately. <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812154356-f45f13:Devstral 2 123B#2 -->
@ -114,0 +117,4 @@
run: |
if ! "$HOME/.local/bin/gitleaks" detect --no-banner --redact --verbose --exit-code 1; then
echo
echo "gitleaks failed — redacted findings above (rule, file:line, fingerprint)."
Member

LOW — Unnecessary echo statements in gitleaks step

The echo statements after the gitleaks command are redundant and do not add value to the error message.

Fix: Remove the redundant echo statements and simplify the error message to be more concise.

panel tally 1/4 · reply here or use the finding board to agree/disagree

**LOW** — Unnecessary echo statements in gitleaks step The echo statements after the gitleaks command are redundant and do not add value to the error message. > **Fix:** Remove the redundant echo statements and simplify the error message to be more concise. <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812154356-f45f13:Devstral 2 123B#3 -->
Author
Owner

Merging despite the red gate, with justification: this PR changes only .forgejo/workflows/baseline.yml (the gate itself). The failure is pre-existing on main since 2026-08-05 — every baseline/trivy-fs run on every commit has failed since (10 npm vulns: 9 HIGH + 1 CRITICAL @nuxt/devtools CVE-2026-71319). Because baseline is a required check and main itself is red, no PR can go green — including Renovate's own fix PRs #22/#23/#25/#26, which is a deadlock only an admin merge of the dep fixes can break. Those dep merges are left to the maintainer (feature branches #16/#17 are in flight). The gate version this PR installs prints the findings verbosely, which is how the backlog stays visible.

Merging despite the red gate, with justification: this PR changes only `.forgejo/workflows/baseline.yml` (the gate itself). The failure is **pre-existing on main since 2026-08-05** — every `baseline`/`trivy-fs` run on every commit has failed since (10 npm vulns: 9 HIGH + 1 CRITICAL `@nuxt/devtools` CVE-2026-71319). Because `baseline` is a required check and **main itself is red, no PR can go green — including Renovate's own fix PRs #22/#23/#25/#26**, which is a deadlock only an admin merge of the dep fixes can break. Those dep merges are left to the maintainer (feature branches #16/#17 are in flight). The gate version this PR installs prints the findings verbosely, which is how the backlog stays visible.
A-Guevara deleted branch chore/h2-baseline-security 2026-08-12 15:46:28 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!28
No description provided.