Repository navigation
test(security): probe production admission for foreign team identities - #4553
Conversation
Add a dispatch-only workflow and script that ask the production API server, with server-side dry-run requests only, whether restrict-github-team-external-identity refuses a foreign GitHub team identity on create and update and still admits the legitimate writes. Part of #3144 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai full review |
|
…es not list A Team the provider created anew carries an identity the policy refuses for re-adoption by design, so the probe ends INCONCLUSIVE there instead of reporting a defect. The swapped probe and the step summary now have their own test coverage, and jq diagnostics no longer reach the log. Part of #3144 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai review |
✅ Action performedReview finished.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (1)
🧰 Additional context used🧠 Learnings (1)📚 Learning: 2026-08-10T13:01:12.782ZApplied to files:
🔇 Additional comments (4)
📝 WalkthroughWalkthroughAdds a Bash probe that checks GitHub Team external-identity admission through server-side dry-run requests and reports enforced, not-enforced, or inconclusive results. Adds a manually dispatched production workflow with branch and confirmation guards. Updates CI to run ShellCheck and the probe tests when the Kubernetes path filter matches. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to No actionable issue remains in the production admission probe, its guarded workflow, or its CI validation. The PR is mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The probe sends non-persisting requests and has explicit execution guards. It follows an existing production-access pattern, but adds another workflow using broad production credentials. Live credential restrictions and deployment protections were not independently verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 28.57% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 2 files. (2 skipped: 2 unsupported.)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Readiness evaluation at
|
Why
The rule that stops a team object from being pointed at a different GitHub team is deployed, but nobody has yet seen production refuse such a change or let the legitimate ones through. The security issue stays open on that missing proof, and the available operator access cannot obtain it.
What
Adds a manually started check that asks production whether it would refuse a foreign team identity and accept the legitimate changes, using trial requests that are never stored. It runs only from the main branch after a typed confirmation, waits its turn behind deployments, and reports enforced, not enforced, or inconclusive.
Part of #3144