Repository navigation
fix(security): pin the community-group repository URL gate to https github.com - #717
Closed
hivecommons-hive[bot] wants to merge 1 commit into
Closed
hivecommons-hive[bot] wants to merge 1 commit into
hivecommons-hive[bot] wants to merge 1 commit into
Conversation
…ithub.com validate-community-groups.mjs checked group.repository with a bare new URL() parse, which succeeds for javascript:, data:, cleartext http, and a userinfo-spoofed authority such as https://github.com@evil.example. It was the only URL gate in data/ that decided nothing about the destination beyond parseability, while validate-case-studies.mjs, validate-radar-reports.mjs, validate-awards.mjs, validate-architectures.mjs and lib/project-card-links.mjs all require https, reject userinfo, and pin the host. Require https, reject userinfo, and pin the host to github.com, which is the only host check-community-group-links.mjs ever writes. The missing-field branch still reports an absent repository on its own. Signed-off-by: hivecommons-hive[bot] <hivecommons-hive@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
Member
|
Superseded by #753, which consolidates the six open security-fix PRs (commits cherry-picked unmodified, authorship and DCO preserved). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
scripts/validate-community-groups.mjsgatedgroup.repositorywith a barenew URL()parse. That parse succeeds forjavascript:alert(1),data:text/html,..., cleartexthttp://, and for a userinfo-spoofedauthority such as
https://github.com@evil.example/cncf/telecom-user-group,whose visible prefix and real host disagree — so the validator passed all of
them.
It was the only URL gate under
data/that decided nothing about thedestination beyond parseability.
validate-case-studies.mjs,validate-radar-reports.mjs,validate-awards.mjs,validate-architectures.mjsandlib/project-card-links.mjsall alreadyrequire
https:, rejecturl.username/url.password, and pin the host to anallow-list.
This change brings the outlier in line: parse, require
https:, rejectuserinfo, and pin the host to
github.com— the only hostscripts/check-community-group-links.mjsever writes. The missing-field branchabove it is unchanged, so an absent
repositoryis still reported once, as"group requires slug, name, and repository", and not also as a bad URL.
Files and functions claimed
scripts/validate-community-groups.mjs— newpublishableRepositoryUrl()helper replaces the
try/catchURL check.tests/validate-community-groups.test.mjs— coverage for the new branch.No other open PR touches either file.
Verification
node --test tests/validate-community-groups.test.mjs— 27/27 pass (was 13),covering
javascript:,data:, cleartext http, userinfo spoofing, a hostthat merely ends in
github.com, a subdomain of it, a whitespace-only value,surrounding whitespace, and an uppercase host.
npm run validate:community-groups— "Validated 2 End User Group links"; therepository's current data is unaffected.
node tests/tools/coverage-report.mjs --check 97 --check-source 99— passes.prettier --check .— clean.Closes #716
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88