Skip to content

fix(security): upgrade action runtimes - #8

Draft
seonghobae wants to merge 1 commit into
shared-container-userfrom
secure-action-deps
Draft

seonghobae wants to merge 1 commit into
shared-container-userfrom
secure-action-deps

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown

Issue for this PR

Dependency-security cycle tracked in ContextualWisdomLab/.github#2356. A local issue cannot be created because this repository has Issues disabled; GitHub REST returned 410.

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

Upgrades both directly shipped GitHub Action runtimes to @actions/core 3.0.1 and @actions/github 9.1.1, removing their Undici 5 paths from the standalone and workspace lockfiles. The blocked private @actions/github/lib/context import is replaced with the public typeof github.context type.

Exact stacked parent: #6 3abe6f3f601ad502d1fa670398778a582e2d98d3. Current exact head/tree: 16f3c4248e0bbdf4550416e32ea9906470ad6f3e / 7071ba4284a950b842758325d9e9794f8539ac2d.

How did you verify your code works?

RCA traced exact-head Security Scan run 36848110099, job 110323068088, to two independent direct-runtime paths: @actions/[email protected] → [email protected] and @actions/[email protected] → @actions/[email protected] → [email protected].

RED: the expanded lockfile contract failed after the GitHub-only upgrade because the Core path remained.

GREEN under Bun 1.3.14: the complete security directory passes 7 tests, 0 failures, 9 assertions; git diff --check passes. The standalone TypeScript check no longer reports the private-export error and still exposes four documented pre-existing package-boundary errors. A full local workspace install is blocked by the existing tree-sitter-powershell node-gyp header extraction failure, so hosted success is not claimed.

Screenshots / recordings

Not applicable; dependency and contract repair only.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

Stack and authority

This PR remains Draft / Proposed / merge HOLD because #6 is a mutable Draft prerequisite. Fresh exact-head test, Security Scan, SAST, review resolution, prerequisite integration, and qualifying approval remain acceptance gates. The GLM 5.2 artifact and development-only Action dependency trees remain separately visible Gap work.

No Force Push, destructive rebase, bypass, wake commit, or predecessor closure was used.

2026-10-03 exact-head hosted terminal state

  • Exact head remains 16f3c4248e0bbdf4550416e32ea9906470ad6f3e.
  • Test run 36911592658 stayed queued from 2026-10-01 19:04 UTC and was automatically cancelled at 2026-10-02 19:04 UTC without producing test evidence.
  • The successful PR-standards context does not replace the missing Test/Security Scan/SAST evidence. This is Draft / Proposed / merge HOLD, not GREEN; no manual rerun, empty wake commit, bypass, or merge is authorized.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for 16f3c4248e0bbdf4550416e32ea9906470ad6f3e (tree 7071ba4284a950b842758325d9e9794f8539ac2d): no blocking source finding in the 10-file stacked delta.

I verified the two direct publication boundaries, the independent @actions/github and @actions/core → @actions/http-client Undici paths, the regenerated lock entries, and the replacement of the blocked private context-type import with the public typeof github.context shape. The regression is bounded to the directly shipped runtimes and does not falsely claim the separately owned artifact/development trees are repaired.

Local fresh evidence: Bun 1.3.14 security directory 7 passed, 0 failed, 9 assertions; git diff --check passed. Hosted test run 36911592658 is queued, not passing. Keep Draft / merge HOLD until exact-head test and security evidence are GREEN and stacked prerequisite #6 is integrated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant