fix: security audit of board verification, scanning invariants, and privacy tiers (closes #18) - #60
Draft
s6pa1rta3n-lab wants to merge 1 commit into
Draft
fix: security audit of board verification, scanning invariants, and privacy tiers (closes #18)#60s6pa1rta3n-lab wants to merge 1 commit into
s6pa1rta3n-lab wants to merge 1 commit into
Conversation
…anning (closes mxx1111#18) - Enforce refund binding to original escrow funder - Enforce escrow ownership to prevent hostile takeover - Validate settle evidence against canonical GitHub PR URLs and task references - Implement NUL framing in scan-repo and fail-closed on unreadable files - Escape GitHub Actions annotation commands - Enforce exact-line allowlist matching - Correct P2 privacy tier documentation to temporary trusted access
|
这个 PR 已经 7 天没有新提交、作者也没有回复,它关联任务上的托管因此一直被占着,既不结算也不释放。
PR 不会被关闭——这是你的工作,随时可以接着做。被释放的只是任务上的认领,任务重新开放给其他人。 如果你还在做,回一句就行。 No commits or author replies for 7 days. The claim is released; this PR stays open. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed / 改了什么
Closes #18
This pull request implements the comprehensive security hardening and audit fixes for the repository and ledger verification engine:
verify.mjssorefundoperations must return funds directly to the originalfromaccount that established the escrow.ledger/pr-evidence.mjsrequiring settlement evidence to be canonical GitHub PR URLs referencing the task, verified as merged or closed/accepted, with valid non-future event timestamps preceding ledger settlement.scripts/scan-repo.mjsto useexecFileSyncwith NUL-delimited output (git ls-files -z) and fail closed (throw) when encountering unreadable tracked files.%,\r,\n,:,,) to prevent command injection in annotations.rule-id:path:line) in.github/scan-allow.txt, dropping wildcard suppression rules.PRIVACY-TIERS.mdand project docs to accurately reflect P2 as temporary trusted access with copyable source rather than unachievable zero-disk guarantees.Acceptance Criteria Checklist
npm testpasses (all 50 unit and integration tests across verifier, scanner, stats, pricing, and pr-evidence pass).npm run ledgerreplays the 27 historical entries with all 11 invariants holding.npm run ledger:prsverifies historical settlement pull requests.npm run scanreports 0 blocking issues.Attestation / 声明
Payout Routing
0xF46C9F6d70C50BF81ef3588AB523a90a594a2F89GCL6OXAMLD75BMTINA6EMRUDWK5THQUSHMYNLSNBCJAPZJHNYJTUNIBC