diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json new file mode 100644 index 0000000000..0837817a13 --- /dev/null +++ b/.github/aw/actions-lock.json @@ -0,0 +1,31 @@ +{ + "entries": { + }, + "containers": { + "ghcr.io/github/gh-aw-firewall/agent:0.25.58": { + "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.58", + "digest": "sha256:a316a2c021accba8a9ea194c75466b0c4a166be6ac783bf8c2d0afd73373dec2", + "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.58@sha256:a316a2c021accba8a9ea194c75466b0c4a166be6ac783bf8c2d0afd73373dec2" + }, + "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58": { + "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58", + "digest": "sha256:43a5cdbe4e1156920dcdaab26d6c6761777d5c6bdc572d7d07b11739fb34c749", + "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58@sha256:43a5cdbe4e1156920dcdaab26d6c6761777d5c6bdc572d7d07b11739fb34c749" + }, + "ghcr.io/github/gh-aw-firewall/squid:0.25.58": { + "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.58", + "digest": "sha256:558682b7b6313a5443cbb3d702899823bd732f991c8b52db6b5b8066abefe7a1", + "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.58@sha256:558682b7b6313a5443cbb3d702899823bd732f991c8b52db6b5b8066abefe7a1" + }, + "ghcr.io/github/gh-aw-mcpg:v0.3.22": { + "image": "ghcr.io/github/gh-aw-mcpg:v0.3.22", + "digest": "sha256:ce5c6f5461b077af0d8e8eb1763436e85153f8e9531117d58a7bdb23de71f00a", + "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.22@sha256:ce5c6f5461b077af0d8e8eb1763436e85153f8e9531117d58a7bdb23de71f00a" + }, + "ghcr.io/github/github-mcp-server:v1.1.0": { + "image": "ghcr.io/github/github-mcp-server:v1.1.0", + "digest": "sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029", + "pinned_image": "ghcr.io/github/github-mcp-server:v1.1.0@sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029" + } + } +} diff --git a/.github/workflows/supply-chain-review.lock.yml b/.github/workflows/supply-chain-review.lock.yml index 0440374c0a..99722a435a 100644 --- a/.github/workflows/supply-chain-review.lock.yml +++ b/.github/workflows/supply-chain-review.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"4510909d7b52684e7b58d97ce0b6c491a28acc18fd6c0b1d3adfa55860b70654","body_hash":"767dbf393fc7c7494b531bc639648d109551e1cb43bd5fa0d2d126827861ba7e","compiler_version":"v0.77.5","strict":true,"agent_id":"copilot","agent_model":"gpt-5.4-nano"} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"835aaf34c5688fe6d4315c8eab49dde1ecd53e9bf49be43ccf4fc41bb63f34f4","body_hash":"ccb05611b0ff5785ed4beddd0e21579d44fbd292b76319f10f570c88bdc42ab4","compiler_version":"v0.77.5","strict":true,"agent_id":"copilot","agent_model":"gpt-5.4-nano"} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"de0fac2e4500dabe0009e67214ff5f5447ce83dd","version":"v6.0.2"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"3ea13c02d765410340d533515cb31a7eef2baaf0","version":"v0.77.5"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.25.58"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.25.58"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.22"},{"image":"ghcr.io/github/github-mcp-server:v1.1.0"},{"image":"node:lts-alpine","digest":"sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14","pinned_image":"node:lts-alpine@sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14"}]} # ___ _ _ # / _ \ | | (_) @@ -16,14 +16,14 @@ # # This file was automatically generated by gh-aw (v0.77.5). DO NOT EDIT. # -# To update this file, edit Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef and run: +# To update this file, edit Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545 and run: # gh aw compile # Not all edits will cause changes to this file. # # For more information: https://github.github.com/gh-aw/introduction/overview/ # # -# Source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef +# Source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545 # # Secrets used: # - COPILOT_GITHUB_TOKEN @@ -145,7 +145,7 @@ jobs: GH_AW_INFO_AWF_VERSION: "v0.25.58" GH_AW_INFO_AWMG_VERSION: "" GH_AW_INFO_FIREWALL_TYPE: "squid" - GH_AW_INFO_FRONTMATTER_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef" + GH_AW_INFO_FRONTMATTER_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545" GH_AW_INFO_BODY_MODIFIED: "false" GH_AW_COMPILED_STRICT: "true" uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -257,20 +257,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF' + cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF' - GH_AW_PROMPT_9fcd1296c4e25283_EOF + GH_AW_PROMPT_6740ff15455080cb_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF' + cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF' Tools: add_comment, submit_pull_request_review, add_labels, missing_tool, missing_data, noop - GH_AW_PROMPT_9fcd1296c4e25283_EOF + GH_AW_PROMPT_6740ff15455080cb_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF' + cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -299,15 +299,15 @@ jobs: {{/if}} - GH_AW_PROMPT_9fcd1296c4e25283_EOF + GH_AW_PROMPT_6740ff15455080cb_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md" fi - cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF' + cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF' {{#runtime-import .github/workflows/supply-chain-review.md}} - GH_AW_PROMPT_9fcd1296c4e25283_EOF + GH_AW_PROMPT_6740ff15455080cb_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -522,9 +522,9 @@ jobs: mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" mkdir -p /tmp/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs - cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_3d652443abcb6121_EOF' + cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_b3e67e93cdb2db2c_EOF' {"add_comment":{"hide_older_comments":true,"max":1},"add_labels":{"allowed":["security:low","security:medium","security:high"]},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"},"report_incomplete":{},"submit_pull_request_review":{"max":1}} - GH_AW_SAFE_OUTPUTS_CONFIG_3d652443abcb6121_EOF + GH_AW_SAFE_OUTPUTS_CONFIG_b3e67e93cdb2db2c_EOF - name: Generate Safe Outputs Tools env: GH_AW_TOOLS_META_JSON: | @@ -757,7 +757,7 @@ jobs: mkdir -p /home/runner/.copilot GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_df9f290c1ebfe6b7_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_d2d29ce847428284_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -798,7 +798,7 @@ jobs: "payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}" } } - GH_AW_MCP_CONFIG_df9f290c1ebfe6b7_EOF + GH_AW_MCP_CONFIG_d2d29ce847428284_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1098,8 +1098,8 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_NOOP_MAX: "1" GH_AW_WORKFLOW_NAME: "Supply Chain Review" - GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md" + GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_NOOP_REPORT_AS_ISSUE: "true" @@ -1116,8 +1116,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "Supply Chain Review" - GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md" + GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} @@ -1135,8 +1135,8 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_MISSING_TOOL_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "Supply Chain Review" - GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md" + GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1151,8 +1151,8 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "Supply Chain Review" - GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md" + GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1167,8 +1167,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "Supply Chain Review" - GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md" + GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_WORKFLOW_ID: "supply-chain-review" @@ -1507,8 +1507,8 @@ jobs: GH_AW_ENGINE_VERSION: "1.0.55" GH_AW_WORKFLOW_ID: "supply-chain-review" GH_AW_WORKFLOW_NAME: "Supply Chain Review" - GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md" + GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md" outputs: code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }} code_push_failure_errors: ${{ steps.process_safe_outputs.outputs.code_push_failure_errors }} diff --git a/.github/workflows/supply-chain-review.md b/.github/workflows/supply-chain-review.md index 55ec7185d5..4806d21555 100644 --- a/.github/workflows/supply-chain-review.md +++ b/.github/workflows/supply-chain-review.md @@ -32,7 +32,7 @@ safe-outputs: allowed: [security:low, security:medium, security:high] submit-pull-request-review: -source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef +source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545 --- # Supply Chain Review @@ -65,7 +65,7 @@ Before collecting external data, identify and exclude internal/private dependenc For each internal dependency found: 1. Remove it from the analysis pipeline — do NOT query OSV.dev, OpenSSF Scorecard, or registry APIs for these packages (they will fail or return irrelevant data). -2. Record the package name, ecosystem, old version, and new version in a separate "Internal Dependencies (Skipped)" list. +2. Record the package name (with `@` replaced by `(at)` for GitHub comment compatibility), ecosystem, old version, and new version in a separate "Internal Dependencies (Skipped)" list. 3. Continue with Step 2 only for the remaining external/public dependencies. If ALL changed dependencies are internal, skip Steps 2-4 and proceed directly to Step 5, posting a report that lists the internal dependencies and notes that no external supply chain analysis was performed. @@ -276,7 +276,18 @@ If no suspicious patterns are found, assign a score of 0-10 and risk level LOW. ## Step 5 — Post Findings as PR Comment -Post a structured report in the following format: +Post a structured report in the following format. + +**CRITICAL: Sanitize all `@` symbols before posting** + +GitHub enforces a maximum of 10 mentions per comment. Package names containing `@` (like `@hyland/core`, `@alfresco/js-api`) are interpreted as user/team mentions and trigger this limit, causing comment post failures. + +**Before generating the comment text**: + +1. Replace **every** `@` symbol in package names with `(at)` — e.g., `@hyland/core` → `(at)hyland/core` +2. Apply this transformation to ALL occurrences: table cells, headings, inline code blocks, findings sections, reason columns +3. This applies to both external and internal dependencies +4. Do NOT skip this step — even if only a few packages are affected, GitHub counts all `@` symbols ```txt ## Supply Chain Security Review @@ -287,15 +298,15 @@ Post a structured report in the following format: ### Internal Dependencies (Skipped) -| Package | Ecosystem | Old Version | New Version | Reason | -|--------------|-----------|-------------|-------------|----------------------------| -| @hyland/core | npm | 3.1.0 | 3.2.0 | Internal (@hyland/* scope) | +| Package | Ecosystem | Old Version | New Version | Reason | +|-------------------|-----------|-------------|-------------|---------------------------------| +| (at)hyland/core | npm | 3.1.0 | 3.2.0 | Internal ((at)hyland/* scope) | _These dependencies are internal packages not available on public registries. External API checks were skipped._ ### Findings -#### `` ( -> ) — +#### `` ( -> ) — **Risk Score**: /100