Skip to content

fix(security): validate projects-born URLs before they render site-wide - #684

Closed
hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
sec/validate-projects-born
Closed

hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
sec/validate-projects-born

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Security Fix

data/projects-born.json was the only hand-maintained data file feeding an <a href> with no validator behind it.

src/components/ProjectsBorn/index.js:28 renders the field verbatim, and that component is mounted in src/theme/Footer/index.js:141 (<ProjectsBorn compact />) as well as its homepage section — so these links appear on every page of the site.

Every sibling data source (awards, metrics, launch-metrics, case-studies, radar-reports, architectures, community-people, community-groups) already has a scripts/validate-*.mjs that parses its URLs and rejects non-https: and userinfo. This file did not, so the only gate was a maintainer noticing a bad value in a JSON diff.

What this changes

Adds scripts/validate-projects-born.mjs, which for every entry:

  • parses url and rejects non-https:, userinfo-bearing, unparseable, blank and non-string values
  • requires name, origin and description to be non-empty strings
  • rejects duplicate name values

Parsing rather than prefix-testing matches checkHttpsUrl() in validate-awards.mjs and checkUrl() in validate-metrics.mjs: /^https:\/\// accepts "https://www.envoyproxy.io@evil.example/", whose visible prefix and real host disagree, and accepts unparseable values such as "https://".

No host allow-list — unlike the cncf.io feeds guarded by validate-radar-reports.mjs and validate-case-studies.mjs, these are legitimately third-party project sites (envoyproxy.io, jaegertracing.io, backstage.io, vitess.io, argoproj.github.io).

Files and functions claimed by this PR

  • scripts/validate-projects-born.mjs (new — checkUrl)
  • tests/validate-projects-born.test.mjs (new)
  • tests/validators-smoke.test.mjs — one line added to READ_ONLY_VALIDATORS
  • package.json — one validate:projects-born script line added in the validate:* block

Registering the script in READ_ONLY_VALIDATORS is what actually puts it on the PR gate; tests/validator-smoke-coverage.test.mjs already enforces that every scripts/validate-*.mjs appears there, so no CI workflow edit is required for this fix to take effect.

This PR is disjoint from the open hold-gated PRs: #676 (scripts/lib/mdx-active-content.mjs), #678 and #680 (tests for import-architectures / svg-active-content). It touches package.json, as #674 does, but on a different line and a different cluster — #674 edits only test:unit:coverage:check, this adds a validate:* entry.

Verification

  • node scripts/validate-projects-born.mjs → Validated 5 born projects (exit 0)
  • node --test tests/validate-projects-born.test.mjs → 19/19 pass
  • npm run test:unit:coverage:check → exit 0; scripts/validate-projects-born.mjs at 100.00% lines / 100.00% regions; src files aggregate rises to 97.97% regions (also clears the stricter --check-source-regions 97 proposed in ci: gate region coverage alongside line coverage #674)
  • npx prettier --check clean on all four files

Still waiting on a human

Issue #683 also notes an optional consistency step: adding a Validate projects born data step to the ten existing validate:* steps in .github/workflows/ci.yml. This agent cannot push it — an ISSUES_AND_PRS token is minted at the contributor tier, which lacks the Workflows permission, so GitHub rejects any push touching .github/workflows/** server-side. The exact YAML is in #683. It is not required for this fix to work; the READ_ONLY_VALIDATORS entry already runs the validator on every pull request.

Closes #683


Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.

— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88

data/projects-born.json was the only hand-maintained data file feeding an
<a href> with no validator behind it. src/components/ProjectsBorn renders
each entry's url verbatim, and that component is mounted in
src/theme/Footer, so the links ship on every page of the site.

Add scripts/validate-projects-born.mjs, which parses every url and rejects
non-https, userinfo-bearing and unparseable values, and requires name,
origin and description to be non-empty and names to be unique. Parsing
rather than prefix-testing matches checkHttpsUrl() in validate-awards.mjs
and checkUrl() in validate-metrics.mjs: /^https:\/\// accepts
"https://www.cncf.io@evil.example/", whose visible prefix and real host
disagree. No host allow-list, since these are legitimately third-party
project sites.

Registering the script in READ_ONLY_VALIDATORS is what puts it on the pull
request gate; tests/validator-smoke-coverage.test.mjs already enforces that
every scripts/validate-*.mjs appears there.

Signed-off-by: hivecommons-hive[bot] <hivecommons-hive@hive.kubestellar.io>
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will automatically remove the hold label once current policy no longer requires a level hold for "sec-check". If this is an outreach PR, a human must review it and remove the label.

@mrbobbytables

Copy link
Copy Markdown
Member

Superseded by #753, which consolidates the six open security-fix PRs (commits cherry-picked unmodified, authorship and DCO preserved).

@mrbobbytables
mrbobbytables deleted the sec/validate-projects-born branch September 28, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent/security Approved by a Hive merger/owner for auto-merge on green CI hive/hosted-available-lke648397-260827-5n31 Approved by a Hive merger/owner for auto-merge on green CI hold security Approved by a Hive merger/owner for auto-merge on green CI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sec-check] data/projects-born.json URLs render as site-wide <a href> with no validator

1 participant