fix(security): validate projects-born URLs before they render site-wide - #684
Closed
hivecommons-hive[bot] wants to merge 1 commit into
Closed
hivecommons-hive[bot] wants to merge 1 commit into
hivecommons-hive[bot] wants to merge 1 commit into
Conversation
data/projects-born.json was the only hand-maintained data file feeding an <a href> with no validator behind it. src/components/ProjectsBorn renders each entry's url verbatim, and that component is mounted in src/theme/Footer, so the links ship on every page of the site. Add scripts/validate-projects-born.mjs, which parses every url and rejects non-https, userinfo-bearing and unparseable values, and requires name, origin and description to be non-empty and names to be unique. Parsing rather than prefix-testing matches checkHttpsUrl() in validate-awards.mjs and checkUrl() in validate-metrics.mjs: /^https:\/\// accepts "https://www.cncf.io@evil.example/", whose visible prefix and real host disagree. No host allow-list, since these are legitimately third-party project sites. Registering the script in READ_ONLY_VALIDATORS is what puts it on the pull request gate; tests/validator-smoke-coverage.test.mjs already enforces that every scripts/validate-*.mjs appears there. Signed-off-by: hivecommons-hive[bot] <hivecommons-hive@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
This was referenced Sep 26, 2026
Member
|
Superseded by #753, which consolidates the six open security-fix PRs (commits cherry-picked unmodified, authorship and DCO preserved). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
data/projects-born.jsonwas the only hand-maintained data file feeding an<a href>with no validator behind it.src/components/ProjectsBorn/index.js:28renders the field verbatim, and that component is mounted insrc/theme/Footer/index.js:141(<ProjectsBorn compact />) as well as its homepage section — so these links appear on every page of the site.Every sibling data source (
awards,metrics,launch-metrics,case-studies,radar-reports,architectures,community-people,community-groups) already has ascripts/validate-*.mjsthat parses its URLs and rejects non-https:and userinfo. This file did not, so the only gate was a maintainer noticing a bad value in a JSON diff.What this changes
Adds
scripts/validate-projects-born.mjs, which for every entry:urland rejects non-https:, userinfo-bearing, unparseable, blank and non-string valuesname,originanddescriptionto be non-empty stringsnamevaluesParsing rather than prefix-testing matches
checkHttpsUrl()invalidate-awards.mjsandcheckUrl()invalidate-metrics.mjs:/^https:\/\//accepts"https://www.envoyproxy.io@evil.example/", whose visible prefix and real host disagree, and accepts unparseable values such as"https://".No host allow-list — unlike the cncf.io feeds guarded by
validate-radar-reports.mjsandvalidate-case-studies.mjs, these are legitimately third-party project sites (envoyproxy.io,jaegertracing.io,backstage.io,vitess.io,argoproj.github.io).Files and functions claimed by this PR
scripts/validate-projects-born.mjs(new —checkUrl)tests/validate-projects-born.test.mjs(new)tests/validators-smoke.test.mjs— one line added toREAD_ONLY_VALIDATORSpackage.json— onevalidate:projects-bornscript line added in thevalidate:*blockRegistering the script in
READ_ONLY_VALIDATORSis what actually puts it on the PR gate;tests/validator-smoke-coverage.test.mjsalready enforces that everyscripts/validate-*.mjsappears there, so no CI workflow edit is required for this fix to take effect.This PR is disjoint from the open hold-gated PRs: #676 (
scripts/lib/mdx-active-content.mjs), #678 and #680 (tests forimport-architectures/svg-active-content). It touchespackage.json, as #674 does, but on a different line and a different cluster — #674 edits onlytest:unit:coverage:check, this adds avalidate:*entry.Verification
node scripts/validate-projects-born.mjs→Validated 5 born projects(exit 0)node --test tests/validate-projects-born.test.mjs→ 19/19 passnpm run test:unit:coverage:check→ exit 0;scripts/validate-projects-born.mjsat 100.00% lines / 100.00% regions;src filesaggregate rises to 97.97% regions (also clears the stricter--check-source-regions 97proposed in ci: gate region coverage alongside line coverage #674)npx prettier --checkclean on all four filesStill waiting on a human
Issue #683 also notes an optional consistency step: adding a
Validate projects born datastep to the ten existingvalidate:*steps in.github/workflows/ci.yml. This agent cannot push it — anISSUES_AND_PRStoken is minted at thecontributortier, which lacks the Workflows permission, so GitHub rejects any push touching.github/workflows/**server-side. The exact YAML is in #683. It is not required for this fix to work; theREAD_ONLY_VALIDATORSentry already runs the validator on every pull request.Closes #683
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88