Skip to content

Commit bdb3e93

Browse files
docs(spec): daily threat-spec review - extend CTR-005/007/009/012 mappings (#53566)
1 parent a851236 commit bdb3e93

1 file changed

Lines changed: 14 additions & 5 deletions

File tree

specs/compiler-threat-detection-spec.md

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ sidebar:
77

88
# GitHub Actions Compiler Threat Detection Specification
99

10-
**Version**: 1.0.23
10+
**Version**: 1.0.24
1111
**Status**: Candidate Recommendation
1212
**Latest Version**: https://github.com/github/gh-aw/blob/main/specs/compiler-threat-detection-spec.md
1313
**Editors**: GitHub Next (GitHub, Inc.)
@@ -78,6 +78,7 @@ This section anchors the specification version to the minimum gh-aw binary versi
7878

7979
| Spec version | Minimum gh-aw binary version | Lock-file compatibility notes |
8080
|--------------|------------------------------|-------------------------------|
81+
| `1.0.24` | `v0.87.1` (or newer) | No new CTR rules; extends existing rule mappings (CTR-005, CTR-006/CTR-009, CTR-007, CTR-012) to cover recently-hardened implementation sites reviewed in this cycle (safe-output field allowlisting, agent-import-path shell escaping, URL-authority userinfo bypass in the markdown/content sanitizer, and generalized wildcard-target validation). No `.lock.yml` schema changes. |
8182
| `1.0.23` | `v0.87.1` (or newer) | Adds normative coverage for framework self-prompt misattribution handling (CTR-025) in threat-detection setup by stripping only the leading framework-generated `<system>...</system>` block before analysis; no `.lock.yml` schema changes (runtime-only detection setup behavior). |
8283
| `1.0.22` | `v0.87.0` (or newer) | Adds validated `threat-detection-suppress` handling and the `threat_detection_suppressions` manifest field, plus optimizer suppression and failure-safeguard conformance coverage. |
8384
| `1.0.21` | `v0.83.6` (or newer) | Editorial correction: the Deprecation Policy subsection is numbered 5.4 to match its parent section; no lock-file compatibility changes. |
@@ -283,14 +284,14 @@ Implementations MUST maintain a clear mapping from each active `CTR-*` rule to c
283284
| CTR-002 Unpinned Action Integrity | `pkg/workflow/*action*.go`, `pkg/workflow/strict_mode_validation*.go` | `pkg/workflow/*action*_test.go`, `pkg/workflow/*strict_mode*_test.go` |
284285
| CTR-003 Unsafe Tool Scope Expansion | `pkg/workflow/tools_validation*.go`, `pkg/workflow/strict_mode_validation*.go` | `pkg/workflow/*tools*_test.go` |
285286
| CTR-004 Sandbox Bypass Configuration | `pkg/workflow/sandbox_validation*.go`, `pkg/workflow/strict_mode_sandbox_validation*.go`, `pkg/workflow/strict_mode_permissions_validation.go` | `pkg/workflow/*sandbox*_test.go` |
286-
| CTR-005 Unsafe Output Route | `pkg/workflow/compiler_safe_outputs*.go`, `pkg/workflow/safe_outputs*.go` | `pkg/workflow/*safe_outputs*_test.go` |
287+
| CTR-005 Unsafe Output Route | `pkg/workflow/compiler_safe_outputs*.go`, `pkg/workflow/safe_outputs*.go`; runtime harness field allowlisting in `actions/setup/js/safe_output_type_validator.cjs` (declared-field enforcement) and patch/manifest differential-parsing hardening in `actions/setup/js/patch_path_helpers.cjs`, `actions/setup/js/manifest_file_helpers.cjs` (patch-parser vs. `git am` protected-file bypass defense) | `pkg/workflow/*safe_outputs*_test.go`, `actions/setup/js/safe_output_type_validator.test.cjs`, `actions/setup/js/patch_path_helpers.test.cjs`, `actions/setup/js/manifest_file_helpers.test.cjs` |
287288
| CTR-006 Template Injection | `pkg/workflow/template_injection_validation.go`, `pkg/workflow/heredoc_validation.go` | `pkg/workflow/template_injection_validation_test.go`, `pkg/workflow/template_injection_validation_fuzz_test.go` |
288-
| CTR-007 Markdown Content Security | `pkg/workflow/markdown_security_scanner.go` | `pkg/workflow/markdown_security_scanner_test.go`, `pkg/workflow/secure_markdown_rendering_test.go` |
289+
| CTR-007 Markdown Content Security | `pkg/workflow/markdown_security_scanner.go`; URL-authority allowlist parity between the stripping and filtering passes (userinfo-prefix bypass, backslash-separator normalization, embedded-whitespace discard) in `actions/setup/js/sanitize_content_core.cjs` | `pkg/workflow/markdown_security_scanner_test.go`, `pkg/workflow/secure_markdown_rendering_test.go`, `actions/setup/js/sanitize_content.test.cjs` |
289290
| CTR-008 Pull Request Target Safety | `pkg/workflow/pull_request_target_validation.go` | `pkg/workflow/pull_request_target_validation_test.go` |
290-
| CTR-009 Shell Expansion in Safe-Outputs | `pkg/workflow/safe_outputs_steps_shell_expansion_validation.go` | `pkg/workflow/safe_outputs_steps_shell_expansion_validation_test.go` |
291+
| CTR-009 Shell Expansion in Safe-Outputs | `pkg/workflow/safe_outputs_steps_shell_expansion_validation.go`; agent-import-path allowlist regex and consistent argument escaping in engine command generation (`pkg/workflow/agent_validation.go` path-character allowlist, `pkg/workflow/shell.go` `shellEscapeArg`/`shellJoinArgs`, `pkg/workflow/engine_helpers.go`) | `pkg/workflow/safe_outputs_steps_shell_expansion_validation_test.go`, `pkg/workflow/engine_agent_import_test.go`, `pkg/workflow/inline_imports_test.go` |
291292
| CTR-010 Expression Safety Allowlist | `pkg/workflow/expression_safety_validation.go`, `pkg/workflow/expression_syntax_validation.go`, `pkg/workflow/runtime_import_validation.go` (`validateRuntimeImportFiles`) | `pkg/workflow/expression_extraction_test.go` |
292293
| CTR-011 Network Firewall Configuration | `pkg/workflow/network_firewall_validation.go`, `pkg/workflow/firewall_validation.go`, `pkg/workflow/strict_mode_network_validation.go` | `pkg/workflow/network_firewall_validation_test.go` |
293-
| CTR-012 Safe-Outputs Wildcard Push Scope | `pkg/workflow/push_to_pull_request_branch_validation.go` | `pkg/workflow/push_to_pull_request_branch_test.go`, `pkg/workflow/push_to_pull_request_branch_warning_test.go` |
294+
| CTR-012 Safe-Outputs Wildcard Push Scope | `pkg/workflow/push_to_pull_request_branch_validation.go`; generalized wildcard-target validation across other safe-output tools so a missing target identifier fails immediately with a tool-specific compiler error rather than deferring to apply time (`pkg/workflow/safe_outputs_tools_generation.go`, `pkg/workflow/safe_outputs_tools_repo_params.go`) | `pkg/workflow/push_to_pull_request_branch_test.go`, `pkg/workflow/push_to_pull_request_branch_warning_test.go` |
294295
| CTR-013 Argument Injection via Package/Image Names | `pkg/workflow/name_validation.go` (shared helper `rejectHyphenPrefixPackages`), `pkg/workflow/npm_validation.go`, `pkg/workflow/pip_validation.go`, `pkg/workflow/docker_validation.go` | `pkg/workflow/argument_injection_test.go` |
295296
| CTR-014 Supply Chain Attack via Install Scripts | `pkg/workflow/run_install_scripts_validation.go` (`validateRunInstallScripts`, `resolveRunInstallScripts`) | `pkg/workflow/run_install_scripts_validation_test.go` |
296297
| CTR-015 Allowed Label Glob Scope | `pkg/workflow/safe_outputs_allowed_labels_validation.go` (`validateSafeOutputsAllowedLabelsGlobScope`) | `pkg/workflow/safe_outputs_allowed_labels_validation_test.go` |
@@ -415,6 +416,14 @@ These optimizer-protocol IDs cover Section 6 norms; they do not add or replace t
415416

416417
## 10. Change Log
417418

419+
### 1.0.24 (2026-08-18)
420+
421+
- Daily optimizer review cycle. Reviewed recent security-relevant changesets: URL-authority userinfo-prefix allowlist bypass in the content sanitizer (`fix-protocol-relative-url-userinfo-bypass`, strengthens CTR-007's `sanitize_content_core.cjs` mapping — camo-proxy exfiltration via `https://allowlisted.com@evil.com/` differential between the stripping and filtering regex passes); patch-parser vs. `git am` protected-file check bypass (`patch-fix-patch-parser-file-protection-bypass`, strengthens CTR-005's file-protection enforcement mapping with `patch_path_helpers.cjs`/`manifest_file_helpers.cjs` diff-header parsing hardening); shell-escaping bypass in engine command generation for crafted agent import paths (`patch-fix-shell-escape-agent-path-injection`, strengthens CTR-009 mapping with `agent_validation.go` path allowlist regex and `shell.go` consistent escaping); generalized wildcard-target safe-outputs validation so missing target identifiers fail at compile time instead of apply time (`patch-generalize-wildcard-target-validation`, strengthens CTR-012 mapping); and hardened safe-output field validation restricting handlers to declared fields plus trusted allowlisted comment-reuse IDs (`patch-harden-safe-output-field-validation`, strengthens CTR-005 mapping). All five items extend existing rule coverage; none introduce a new threat class requiring a new `CTR-*` rule.
422+
- Evaluated additional non-security or already-covered items from the same review window: MCP actor validation runtime flag (not a compiler detection rule), cross-repo allowlist validation hardening (already covered by CTR-005/CTR-012), MCP config schema validation wiring (CTR-003/CTR-011 covered), detection-job/OTLP-OIDC/discussions permission fixes (CTR-001 scope, operational correctness rather than new detectable threat class), git-identity env var injection and DIFC proxy wiring for pre-agent steps (defense-in-depth hardening, no new compiler-detectable pattern), and dependency/documentation-only changes.
423+
- Extended Section 7.1 baseline rule mapping table for CTR-005, CTR-006/CTR-007 (no change to CTR-006 row), CTR-009, and CTR-012 with the concrete implementation and test references identified above.
424+
- Updated Section 2 spec-to-implementation sync table with version 1.0.24 entry.
425+
- No `SLA_BREACH` suppression findings and no `threat-detection-suppress` annotations were present in the reviewed diffs during this cycle.
426+
418427
### 1.0.23 (2026-08-16)
419428

420429
- Added CTR-025 Framework Self-Prompt Misattribution to Section 5.1, documenting the existing runtime behavior that strips only the leading framework-generated `<system>...</system>` block before threat analysis.

0 commit comments

Comments
 (0)