fix(browserext): skip protected browser reads on macOS 27 - #226
Merged
ashishkurmi merged 2 commits intoSep 23, 2026
Merged
Conversation
raysubham
force-pushed
the
fix/tcc-protected-reads
branch
2 times, most recently
from
September 23, 2026 16:25
94b06e1 to
debdf50
Compare
raysubham
force-pushed
the
fix/tcc-protected-reads
branch
from
September 23, 2026 16:45
debdf50 to
abe234f
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Two unresolved moderate findings require changes and final human review.
Review effort: Lite
Findings: None
What changed in this PR
Updates browser-extension inventory to honor macOS 27 TCC protections while preserving pre-27 behavior.
Changes:
- Passes OS versions into browser detection.
- Adds version-aware TCC tests and live Darwin validation.
- Documents the fix in the 1.17.0 changelog.
| File | Summary |
|---|---|
internal/telemetry/telemetry.go |
Passes OS version to enterprise scanning. |
internal/scan/scanner.go |
Passes OS version to community scanning. |
internal/detector/browserext/tcc_compat_test.go |
Tests version-dependent TCC behavior. |
internal/detector/browserext/live_darwin_test.go |
Adds live Darwin validation; moderate finding, 1 vote, regarding unbounded external command execution. |
internal/detector/browserext/detector.go |
Applies OS-version-aware protected-path handling; moderate finding, 1 vote, regarding malformed version validation. |
internal/detector/browserext/detector_test.go |
Updates macOS compatibility coverage. |
CHANGELOG.md |
Records the macOS 27 fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
ashishkurmi
approved these changes
Sep 23, 2026
ashishkurmi
pushed a commit
that referenced
this pull request
Sep 24, 2026
#224 replaced the local delta switch with tenant authorization but left the changelog claiming the protocol is "on by default" with use_legacy_package_scan defaulting to false. Both halves are now wrong: the flag and the scan-state env overrides are gone, and a run only sends deltas when the run-config check-in returns package_scan.delta_enabled — missing, null and false all select legacy full-snapshot reporting. #225 also filed its two upload fixes under a fresh [Unreleased] while #218 and #226 filed inside [1.17.0]. Nothing is tagged yet, so all of it ships in 1.17.0; fold them in and drop the empty section. Date moves to the 24th, the day the checks finished green. Signed-off-by: Swarit Pandey <swarit@stepsecurity.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Narrowed to browser-extension inventory only for v1.17.0. Other scanner work is preserved in draft PR #227 for team discussion.
Change
Validation
Limits
This addresses the reproduced browser access notification. Other scanner permission gaps remain for the separate draft and are not covered by this fix. Protected browser inventory on macOS 27 is intentionally skipped. No permissions, customer policies, managed installation files or backend contracts are changed.
One signed commit. Do not merge without owner approval.