Commit cb7fa31
authored
fix(ci): harden release and CodeQL checks (#164)
## Related Issue
No issue. This maintainer follow-up fixes failed `main` Release run
32620664188 and the linked CodeQL configuration warning.
## Problem
The Nix lock freshness check preferred a release branch's stale upstream
over the current default branch. Changesets release PRs could therefore
fail after they reset onto a newer `main`. The CodeQL analysis also
emitted an oversized related-location warning because public OAuth
endpoint identifiers flowed directly into a SHA-256 filename fingerprint
and were classified as password-like values.
## What changed
- Compare lock and flake changes with `origin/HEAD`, then `origin/main`,
before a branch upstream.
- Cover stale release upstreams and real lock-only feature changes with
regression tests.
- Encode public endpoint identity as UTF-8 bytes before hashing in both
credential-name implementations. This keeps the exact existing digest
while preserving the full CodeQL security suite.
- Pin the existing scoped credential key in its test to protect
compatibility.
## Verification
- `pnpm lint`
- `pnpm run typecheck`
- `pnpm run test`
- `pnpm run build`
- `nix build .#pythinker-code`
- Focused Nix freshness, OAuth, and datasource plugin tests
- `pnpm run sherif`
- `node scripts/check-nix-workspace.mjs`
- Independent security, release-validation, and identifier audits: no
findings
## Checklist
- [x] I have read the
[CONTRIBUTING](https://github.com/PyModel/pythinker-code/blob/main/CONTRIBUTING.md)
document.
- [x] No related issue is required for this maintainer CI and security
follow-up.
- [x] I have added tests that prove the fixes work.
- [x] Ran `gen-changesets`; no changeset because behavior and published
output are unchanged.
- [x] No documentation update is needed because the change only repairs
internal validation and equivalent digest input encoding.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved release-branch checks to detect stale pinned hashes using the
current default remote branch.
* Updated OAuth and data-source credential hashing to consistently use
UTF-8 encoding.
* Refined diagnostics to more accurately describe potentially stale
hashes.
* **Tests**
* Added coverage for release-branch hash validation, including stale
tracking and lock-only changes.
* Strengthened OAuth key tests with exact expected derived values.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->1 parent 0b3f72d commit cb7fa31
5 files changed
Lines changed: 111 additions & 12 deletions
File tree
- apps/pythinker-code/test/scripts
- packages/oauth
- src
- test
- plugins/official/pythinker-datasource/bin
- scripts
Lines changed: 89 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
333 | 333 | | |
334 | 334 | | |
335 | 335 | | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
336 | 339 | | |
337 | | - | |
| 340 | + | |
338 | 341 | | |
339 | 342 | | |
340 | 343 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
65 | | - | |
| 64 | + | |
66 | 65 | | |
67 | 66 | | |
68 | 67 | | |
| |||
Lines changed: 4 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
299 | 299 | | |
300 | 300 | | |
301 | 301 | | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
302 | 305 | | |
303 | | - | |
| 306 | + | |
304 | 307 | | |
305 | 308 | | |
306 | 309 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
26 | 31 | | |
27 | 32 | | |
28 | | - | |
29 | | - | |
| 33 | + | |
| 34 | + | |
30 | 35 | | |
31 | 36 | | |
32 | 37 | | |
| |||
57 | 62 | | |
58 | 63 | | |
59 | 64 | | |
60 | | - | |
| 65 | + | |
61 | 66 | | |
62 | 67 | | |
63 | 68 | | |
| |||
0 commit comments