chore(foundation): converge AnyIO and CodeQL endpoint repairs - #2352
seonghobae wants to merge 14 commits into
Conversation
Semgrep OSS and Bandit B310 Medium alerts on main flagged dynamic urllib use in CodeQL identity and Strix evidence helpers. Fail closed unless the URL is https://api.github.com so file:// and arbitrary hosts cannot reach urlopen. Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.0 to 4.14.2. - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.14.0...4.14.2) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Replace retired urllib urlopen monkeypatches with direct CodeQL and Strix dedicated-opener patches. Remove the PR-specific global conftest bridge so both security helpers exercise the same explicit transport boundary without live network access.
Clears Bandit/Semgrep B310 on shared scripts/ci urlopen so the anyio bump is not blocked by unrelated SAST.
Restore the unrelated #2269 URL-opener paths to protected main while retaining the AnyIO 4.14.2 pin and hashes. The URL/redirect responsibility remains in canonical #2279; this PR owns only the dependency security update. Validated with 56 focused tests, 3,335 full tests plus 28 skipped/40 subtests, warnings-as-errors, diff check, and pip-audit reporting no known vulnerabilities.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh exact-producer receipt (2026-09-23): run |
|
Read-only technical review of exact head The three-dot diff is limited to two files. The The separate current-head Succession: #2286@ PR #2352 remains Draft, |
Why this consolidation exists
Two canonical one-file foundation owners are mutually gating on protected
main@e6334e229581a918e2f22de18733b76fa65d7e71:anyio 4.14.0 -> 4.14.2.This Draft is a provenance-preserving integration vehicle, not a third semantic owner.
Exact integration
Exact head:
f1a8dc813e6dba4e4905bf3e1b770b6d44344944. It changes exactly:requirements-strix-ci-hashes.txtfrom chore(deps): bump anyio from 4.14.0 to 4.14.2 #2278;tests/test_organization_commercial_readiness_loop_receipt_contract.pyfrom repair(codeql): restore exact endpoint-set membership #2351.No workflow, gate, permission, provider/model, runtime or mutable-dependency delta is added here.
Current exact-head evidence — 2026-09-24 KST
35805450561: SUCCESS35805450596: SUCCESS35805450386: SUCCESS35805450371: SUCCESS35805450471: FAILUREThe required CodeQL failure is a current-generation sequencing/reconciliation specimen. Python compatibility
107036649617and Actions compatibility107036649620readverdict=pendingand failed closed before coordinator107076139478dispatched the producer.The exact producer is run
35841640640, bound to.github#2352@f1a8dc813..., protected basee6334e229..., required run35805450471. Its job graph is fully terminal:validate-dispatch107117846461: SUCCESS.CodeQL dispatch scan (python)107179921158: FAILURE.CodeQL dispatch scan (actions)107179921308: FAILURE.settle exact required run107247432911: SUCCESS.Both language scans successfully materialized the exact head, initialized/analyzed CodeQL, passed the Medium+ SARIF gate, preserved SARIF, and published dispatch status. The Python specimen records
CODEQL_SARIF files=1 results=0 medium_plus=0. Both fail only atVerify GHAS base/head CodeQL configuration identity, wherecodeql_ghas_configuration_identity.pycalls the target repository'scode-scanning/analysesendpoint and receives HTTP 403Resource not accessible by integration. The target app token also cannot publish status (403), while the bounded same-repositorygithub-tokenfallback successfully publishes dispatch status.The settlement job succeeded. Queue starvation is therefore not the current #2352 diagnosis. The remaining defect is the central GHAS configuration-identity credential/permission boundary plus lifecycle ordering: the required compatibility shards failed before terminal producer evidence existed, and the later producer cannot retroactively make that already-terminal required run GREEN.
This is not a CodeQL source finding and does not indicate another #2278/#2351 semantic change.
Canonical repair path
Current owner topology is now explicit:
0d68d7a8435652edc288d7bb3dfb06a7c8a59eb6owns fail-closed GHAS credential selection and may select only a credential that actually proves targetcode-scanning/analysesread access.42e3f7a8cbb03b117c898d3e125af87a5c6ce86bhas been returned to Draft because live parent fix(strix): resolve evidence binder from trusted source #2291 advanced and the branch is now ahead 40 / behind 3 / diverged.1794626af3473ef23b9c2e678c3f06fd6c11636fowns the trusted Strix binder parent repair and still awaits canonical AnyIO owner chore(deps): bump anyio from 4.14.0 to 4.14.2 #2278 plus fresh terminal acceptance.Preserve fail-closed identity verification. Do not delete the proof, treat clean SARIF as sufficient by itself, synthesize a status, duplicate target permission logic here, move #2278/#2351 source, or broadly rerun.
PR-0 / landing rule
Keep #2278 and #2351 open while this Draft is unmerged. Only protected integration with both parent deltas preserved and authentic terminal gates can make this a verified successor.
Keep this PR Draft until the central parent/admission/permission chain above is protected, the exact producer/identity/reconciliation path is terminal-success, and a qualifying independent non-author current-head approval exists.
No self-approval, force push, destructive rebase, synthetic status, bypass, blind rerun, no-op wake commit, scanner suppression, permission broadening, predecessor-evidence transfer, or gate weakening.