Harden generated evidence file permissions - #4
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The first CodeQL scan on
mainfound high-severity alertpy/overly-permissive-file: generated evidence was explicitly staged as world-readable (0644) before atomic replacement. The browser capture scripts used the same permissive temporary-output mode.What changed
0600) before fsync and atomic replacement0600boundary to PNG, rendered DOM, and capture-attestation staging in both browser capture scripts0644staging pathCommitted evidence remains ordinary public Git content (
100644); the hardening concerns temporary local generation before publication.Reproducible evidence
Final head:
ad69434fb70753f19fe58ab20313a91750d08cb857b5b551c6dd9ae37d35d2f9984d93d683a5165a9038269447: exact 24-file inventory; every entry a regular file with mode100600; no duplicates, symlinks, absolute paths, or traversale539db1152e8b1d66ee543d045739851991deb2e1a45174eb4358621efd4e17ead1f615da03d2e0570a4b3b26603c310058964bfbc5dda201d176de8107e4d63Final validation
1591903166onrefs/pull/4/mergef9bcf2fb3d49539132700873a2aa97591b7bc8b5and final headad69434fb70753f19fe58ab20313a91750d08cb8History integrity
The branch is five commits ahead and zero behind
main. Every branch commit has exactly one parent and both author and committer are Omar Ibrahim 31526072+omar07ibrahim@users.noreply.github.com. No force-push, squash, rebase, amend, or merge commit was used.