fix(security): upgrade action runtimes - #8
seonghobae wants to merge 1 commit into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Thanks for your contribution! This PR doesn't have a linked issue. All PRs must reference an existing issue. Please:
See CONTRIBUTING.md for details. |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for 16f3c4248e0bbdf4550416e32ea9906470ad6f3e (tree 7071ba4284a950b842758325d9e9794f8539ac2d): no blocking source finding in the 10-file stacked delta.
I verified the two direct publication boundaries, the independent @actions/github and @actions/core → @actions/http-client Undici paths, the regenerated lock entries, and the replacement of the blocked private context-type import with the public typeof github.context shape. The regression is bounded to the directly shipped runtimes and does not falsely claim the separately owned artifact/development trees are repaired.
Local fresh evidence: Bun 1.3.14 security directory 7 passed, 0 failed, 9 assertions; git diff --check passed. Hosted test run 36911592658 is queued, not passing. Keep Draft / merge HOLD until exact-head test and security evidence are GREEN and stacked prerequisite #6 is integrated.
Issue for this PR
Dependency-security cycle tracked in ContextualWisdomLab/.github#2356. A local issue cannot be created because this repository has Issues disabled; GitHub REST returned 410.
Type of change
What does this PR do?
Upgrades both directly shipped GitHub Action runtimes to
@actions/core3.0.1 and@actions/github9.1.1, removing their Undici 5 paths from the standalone and workspace lockfiles. The blocked private@actions/github/lib/contextimport is replaced with the publictypeof github.contexttype.Exact stacked parent: #6
3abe6f3f601ad502d1fa670398778a582e2d98d3. Current exact head/tree:16f3c4248e0bbdf4550416e32ea9906470ad6f3e/7071ba4284a950b842758325d9e9794f8539ac2d.How did you verify your code works?
RCA traced exact-head Security Scan run
36848110099, job110323068088, to two independent direct-runtime paths:@actions/[email protected] → [email protected]and@actions/[email protected] → @actions/[email protected] → [email protected].RED: the expanded lockfile contract failed after the GitHub-only upgrade because the Core path remained.
GREEN under Bun 1.3.14: the complete security directory passes 7 tests, 0 failures, 9 assertions;
git diff --checkpasses. The standalone TypeScript check no longer reports the private-export error and still exposes four documented pre-existing package-boundary errors. A full local workspace install is blocked by the existingtree-sitter-powershellnode-gyp header extraction failure, so hosted success is not claimed.Screenshots / recordings
Not applicable; dependency and contract repair only.
Checklist
Stack and authority
This PR remains Draft / Proposed / merge HOLD because #6 is a mutable Draft prerequisite. Fresh exact-head test, Security Scan, SAST, review resolution, prerequisite integration, and qualifying approval remain acceptance gates. The GLM 5.2 artifact and development-only Action dependency trees remain separately visible Gap work.
No Force Push, destructive rebase, bypass, wake commit, or predecessor closure was used.
2026-10-03 exact-head hosted terminal state
16f3c4248e0bbdf4550416e32ea9906470ad6f3e.