Build SynSec v0.2 multi-scanner repository security MVP - #2
Draft
cmahmud wants to merge 1133 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Work in progress toward a production-oriented, repository-first SynSec v0.2 release. This PR intentionally remains draft while major production roadmap items are unfinished.
Implemented in this branch
network=none, no host control socket mounts, and no explicit child credential environment. CI executes this boundary.checkov,grype, andsyftadapters. Hosted AI review remains disabled because it is a separate outbound disclosure boundary.*gin.Contextaccess and a separate bounded one-local forwarding layer. Koa has equivalent framework-specific directional layers for strictKoa routerentrypoints: direct request access must occur on the exact sink line or same line as one direct resolved call, while one-local forwarding requires an exactconstassignment, exactly one later occurrence, a bounded forward distance, and one unchanged sole-argument call. Koa request sources are limited torequest.body, query, params, headers/get(), and cookies;ctx.bodyis rejected as response state. Generic Node routes, mutable/multi-use locals, aliases, destructuring, transforms, wider propagation, and deeper forwarding fail closed. Bare localexecute/querylexical collisions are not upgraded into database flow without member-qualified database-style sink syntax. Cross-module Koa named handlers reuse the existing conservative repository-local import resolver while preserving Koa framework identity.Security interpretation
Repository content, scanner output, webhook payloads, stored artifacts, backend errors, CLI input, and externally supplied metadata are untrusted and bounded. Static evidence, AI output, scanner absence, readiness declarations, provisioning output, mounted credential snapshots, ownership/re-verification state, scheduler completion, maintenance/lifecycle/recovery observations, operator status, host profiles, durable zero-lease observations, upgrade assessments, worker-host execution, OCI configuration, and release-readiness output do not by themselves establish runtime exposure, effective authorization, exploitability, future GitHub access, fleet-wide readiness, complete scanner coverage, deployment success, or absence of vulnerabilities.
The project remains defensive and repository-first. This PR does not add autonomous live-target exploitation, credential harvesting, secret exfiltration, persistence on targets, destructive target behavior, arbitrary outbound targeting, or silent scope expansion.
Still unfinished before production release
package-lock.json; CI therefore still usesnpm install. Generate a lockfile only from a verified dependency graph, then move CI tonpm ci.Validation expectation
Changes are expected to pass build, typecheck, the full Node 20/24 test matrix, machine-readable release-readiness invariant assessment, real PostgreSQL shared-state/ownership/conformance coverage, and enforced OCI scanner-sandbox integration before the branch is treated as green. The PR should remain draft until the remaining major production roadmap items above are resolved.