Skip to content

fix(secrets): centralize governed name audit - #349

Merged
Lutar, Stephen P. (stephenlutar2-hash) merged 1 commit into
mainfrom
fix/governed-secret-health-v3-signed
Jul 28, 2026
Merged

fix(secrets): centralize governed name audit#349
Lutar, Stephen P. (stephenlutar2-hash) merged 1 commit into
mainfrom
fix/governed-secret-health-v3-signed

Conversation

@stephenlutar2-hash

@stephenlutar2-hash Lutar, Stephen P. (stephenlutar2-hash) commented Jul 27, 2026

Copy link
Copy Markdown
Member

Rollback: Revert through a protected pull request. Do not restore the expired PAT lane.
Labels: PROVED signed no-value audit contract; MEASURED all four required names present through governed machine identity; NOT CLAIMED credential validity from name presence.

Satisfies

Satisfies: C-158.

Measured root cause

The former szl-doctrine secret-health lane depended on an expired long-lived SECRET_HEALTH_TOKEN PAT. qillqaq has not yet been approved for repository and organization Secrets: read, while the explicitly governed organization token remains available read-only in the control-plane repository.

Permanent replacement

  • centralize the organization-wide audit in .github;
  • version the exact repository/name policy;
  • request only metadata plus repository and organization secret-name read from qillqaq;
  • use the existing governed organization token read-only until the App permission upgrade is approved;
  • distinguish PRESENT, MISSING, and UNAVAILABLE without conflating authorization failure with a missing secret;
  • persist only repository/name states and a machine-identity source label;
  • prohibit secret values, token values, token metadata, prefixes, lengths, hashes, or expiration data from the receipt;
  • add network-free adversarial tests and a 90-day immutable Actions receipt.

Clean signed lineage

This is the exact-tree signed replacement for #342. Bounded materializer run 30255431491 copied all four permanent files byte-for-byte from head 942c4318c8717bb44708dd6eab9fae1030746811 and created one GitHub-verified signed commit on current protected main:

3e36676ef820c1f6fb9837ec5d00725305ce4abb

The four-commit unsigned predecessor remains preserved; no force push or history rewrite was used.

Exact verification

The predecessor tree passed Governed Secret Health, CI, Tests, CodeQL, Trivy, Gitleaks, DCO, pinning, doctrine, staging, bootstrap invariants, all eight FORGE-9 gates, and qillqaq attestation. Its immutable receipt reported:

  • authentication source: governed-fallback;
  • required names present: 4;
  • missing: 0;
  • unavailable: 0;
  • secret values requested or recorded: false;
  • token values or metadata recorded: false.

Protected checks on this signed one-commit replacement are authoritative for merge.

Labels

Labels: PROVED signed no-value audit contract; MEASURED all four required names present through governed machine identity; NOT CLAIMED credential validity from name presence.

Rollback

Revert through a protected pull request. Do not restore the expired PAT lane.

Risk class

Risk: C — organization-wide read-only secret-name health control and machine-identity migration.

Solo-Operator-Authorization: confirmed

Signed-off-by: Stephen Lutar stephenlutar2@gmail.com

Signed-off-by: Stephen Lutar <stephenlutar2@gmail.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@qillqaq-attestor qillqaq-attestor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ATTESTED. All Section 18 gates green. Merge BAP sha256: d34b64e1e47a8a6222e9426eabfcc84afb4246edc88777eb3a304f9cd7262926

@github-actions
github-actions Bot added this pull request to the merge queue Jul 28, 2026
@stephenlutar2-hash
Lutar, Stephen P. (stephenlutar2-hash) removed this pull request from the merge queue due to a manual request Jul 28, 2026
Merged via the queue into main with commit 99b1c61 Jul 28, 2026
34 of 35 checks passed
@stephenlutar2-hash
Lutar, Stephen P. (stephenlutar2-hash) deleted the fix/governed-secret-health-v3-signed branch July 28, 2026 04:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant