Skip to content

fix(security): pin the community-group repository URL gate to https github.com - #717

Closed
hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
sec/community-groups-url-gate
Closed

hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
sec/community-groups-url-gate

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Security Fix

scripts/validate-community-groups.mjs gated group.repository with a bare
new URL() parse. That parse succeeds for javascript:alert(1),
data:text/html,..., cleartext http://, and for a userinfo-spoofed
authority such as https://github.com@evil.example/cncf/telecom-user-group,
whose visible prefix and real host disagree — so the validator passed all of
them.

It was the only URL gate under data/ that decided nothing about the
destination beyond parseability. validate-case-studies.mjs,
validate-radar-reports.mjs, validate-awards.mjs,
validate-architectures.mjs and lib/project-card-links.mjs all already
require https:, reject url.username/url.password, and pin the host to an
allow-list.

This change brings the outlier in line: parse, require https:, reject
userinfo, and pin the host to github.com — the only host
scripts/check-community-group-links.mjs ever writes. The missing-field branch
above it is unchanged, so an absent repository is still reported once, as
"group requires slug, name, and repository", and not also as a bad URL.

Files and functions claimed

  • scripts/validate-community-groups.mjs — new publishableRepositoryUrl()
    helper replaces the try/catch URL check.
  • tests/validate-community-groups.test.mjs — coverage for the new branch.

No other open PR touches either file.

Verification

  • node --test tests/validate-community-groups.test.mjs — 27/27 pass (was 13),
    covering javascript:, data:, cleartext http, userinfo spoofing, a host
    that merely ends in github.com, a subdomain of it, a whitespace-only value,
    surrounding whitespace, and an uppercase host.
  • npm run validate:community-groups — "Validated 2 End User Group links"; the
    repository's current data is unaffected.
  • node tests/tools/coverage-report.mjs --check 97 --check-source 99 — passes.
  • prettier --check . — clean.

Closes #716


Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.

— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88

…ithub.com

validate-community-groups.mjs checked group.repository with a bare
new URL() parse, which succeeds for javascript:, data:, cleartext http,
and a userinfo-spoofed authority such as https://github.com@evil.example.
It was the only URL gate in data/ that decided nothing about the
destination beyond parseability, while validate-case-studies.mjs,
validate-radar-reports.mjs, validate-awards.mjs, validate-architectures.mjs
and lib/project-card-links.mjs all require https, reject userinfo, and pin
the host.

Require https, reject userinfo, and pin the host to github.com, which is
the only host check-community-group-links.mjs ever writes. The
missing-field branch still reports an absent repository on its own.

Signed-off-by: hivecommons-hive[bot] <hivecommons-hive@hive.kubestellar.io>
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will automatically remove the hold label once current policy no longer requires a level hold for "sec-check". If this is an outreach PR, a human must review it and remove the label.

@mrbobbytables

Copy link
Copy Markdown
Member

Superseded by #753, which consolidates the six open security-fix PRs (commits cherry-picked unmodified, authorship and DCO preserved).

@mrbobbytables
mrbobbytables deleted the sec/community-groups-url-gate branch September 28, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sec-check] validate-community-groups.mjs accepts any URL scheme for group.repository — the only unpinned URL gate in data/

1 participant