Skip to content

[v1.0] Harden release provenance gate after post-merge review #376

Description

@codeforester

Goal

Close the correctness and coverage gaps identified after #375 merged, keeping the release provenance gate fail-closed and maintainable.

Findings from the #375 post-merge review

  • GITHUB_EVENT_PATH is parsed with type=Path and a string default, so an unset value becomes Path('.'); the intended missing-event guard is unreachable and produces a confusing directory-read error.
  • _git_output("rev-parse", "--is-shallow-repository") converts Git failures into an empty string that is interpreted as False, allowing the shallow-history check to pass on command failure.
  • The tests exercise only validate_release_provenance() and not the production main() entrypoint, event-payload parsing, or Git wrapper failure paths.
  • The deleted-tag event branch lacks a direct regression test.
  • The workflow test does not independently prove that both publish and attest retain the provenance dependency.
  • The production_release expression contains an unnecessary disjunct that obscures the actual branch-publication rule.
  • The v-prefixed-tag rule is duplicated between validate_release_ref.py and validate_release_provenance.py; extract a shared helper in scripts/release_metadata_helpers.py.

References: #375 post-merge discussion, shallow-history comment, entrypoint coverage comment, deleted-tag test comment, workflow assertion comment, cleanup comment, and shared-helper finding.

Scope

  • Make missing event-payload input explicit and test it through the real command entrypoint.
  • Treat every Git inspection failure as a validation error; never coerce an unknown repository state into a safe boolean.
  • Add deleted-tag coverage and Git-wrapper failure coverage.
  • Assert the provenance dependency separately for publication, attestation, and GitHub Release jobs.
  • Simplify the production-dispatch condition.
  • Centralize the v-prefix tag validation and keep both validators on the shared helper.

Acceptance criteria

  • Missing GITHUB_EVENT_PATH fails with a clear validation error before attempting to read ..
  • A failed shallow-state Git query fails closed.
  • The deleted-tag negative path is covered.
  • At least one test invokes the production validator entrypoint and exercises event-payload parsing.
  • Workflow tests fail if either publish, attest, or release loses the provenance dependency.
  • Both release validators use one shared v-prefix helper.
  • Full tests, Ruff, strict mypy, and workflow validation pass.

Project Fields

  • Status: Backlog
  • Priority: P1
  • Area: Security
  • Initiative: v1.0 Readiness
  • Size: M

Ownership

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

securitySecurity hardening or vulnerability work

Type

No type

Projects

  • Status
    In Review

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions