[compiler-threat-spec] docs: sync compiler threat spec 1.0.30 changelog and mapping audit - #58902
Conversation
The specification header and Section 2 sync table were previously bumped to version 1.0.30 documenting the CTR-001 status-function guard mapping addition, but Section 7.2 (Mapping Audit) and Section 10 (Change Log) were never updated to match, violating the mandatory Section 7.3 sync protocol. Verified the CTR-001 status-function guard (guardIfAgainstStatusFuncBypass / ifExpressionContainsStatusFunc in pkg/workflow/compiler_builtin_job_augmentation.go) is implemented and covered by existing tests in pkg/workflow/compiler_custom_jobs_test.go. Also reviewed open critical/high code-scanning alerts via GitHub MCP; all are outside compiler conformance targets or are self-scan findings from the daily-malicious-code-scan/daily-semgrep-scan workflows, so no new CTR-* rule is required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@copilot Please take the next forward-progress pass on PR #58902.
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
Rechecked PR #58902 at HEAD |
@copilot Please take the next forward-progress pass on PR #58902.
Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
Rechecked PR #58902 at HEAD |
|
@copilot please take a look at this PR and move it forward. If there are review comments, address them and resolve threads where appropriate. If the branch is behind or needs refresh, update it. Then run the
|
|
✅ This PR is from a trusted team member (GitHub Actions bot). Per the CONTRIBUTING.md guidelines, GitHub Actions and core team automation are treated as trusted contributions and bypass the standard checklist. PR Summary: This is an auto-generated documentation update from the Daily Compiler Threat Spec Optimizer workflow, syncing the specification's audit log and changelog. Scope: documentation only — no compiler/parser source changes. ✅ Ready for review — this aligns with the project's daily maintenance protocol for threat-spec conformance. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
Rechecked PR #58902 at HEAD |
|
@copilot please take the next forward-progress step on this PR. Refresh the branch if needed, address unresolved review feedback and checks, and finish with the Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
Rechecked PR #58902 after the branch refresh; HEAD is now |
@copilot Please re-check PR #58902 on the latest HEAD, confirm whether any maintainer-facing blocker remains beyond routine CI/reviewer completion, and run the
|
Rechecked PR #58902 at latest HEAD |
@copilot Please take the next forward-progress pass on PR #58902.
|
Rechecked PR #58902 at HEAD |
|
@compact changelog |
@copilot Please take the next forward-progress pass on PR #58902.
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Compacted the 1.0.30 changelog entry in commit |
@copilot Please take the next forward-progress pass on PR #58902.
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
Rechecked PR #58902 at HEAD |
|
🎉 This pull request is included in a new release. Release: |
Summary
Daily compiler threat spec optimizer run for 2026-09-06. No compiler/parser source changes were required — this run found and fixed a documentation-sync gap in the spec itself.
Threats Reviewed
8fb0a67); no new compiler/parser diffs were available beyond the existing baseline (all prior spec-tracked changes, e.g. Playwright sandbox flag emission, remain accurately mapped).go/bad-redirect-check(#674, [Custom Engine Test] Test Issue Created by Custom Engine #669, Codex fails to report failure if unauthorised #668, [Custom Engine Test] Test Pull Request - Custom Engine Safe Output #667),go/allocation-size-overflow(Hello from Claude #672),js/http-to-file-access([Custom Engine Test] Test Pull Request - Custom Engine Safe Output #663) — all inpkg/cli/orscripts/, outside this spec's conformance targets (pkg/workflow/,pkg/parser/,actions/setup/).workflow-out-of-context(#653),workflow-go-graphql-injection-sprintf(#651, [Custom Engine Test] Test Issue Created by Custom Engine #652) — self-scan findings from thedaily-malicious-code-scan/daily-semgrep-scanworkflows, not compiler-generated-workflow threats.CTR-*rule required for any of the above.threat-detection-suppressannotations found in live workflow source → no SLA_BREACH findings.Already Covered / Spec-Only Fix
Spec-to-implementation sync gap (already covered, spec was inconsistent): The specification header and Section 2 sync table had already been bumped to version
1.0.30, documenting theCTR-001 Privilege Escalationmapping addition for the status-function guard on compiler-owned prerequisites (guardIfAgainstStatusFuncBypass,ifExpressionContainsStatusFuncinpkg/workflow/compiler_builtin_job_augmentation.go). However, Section 7.2 (Mapping Audit) and Section 10 (Change Log) were never updated to match — violating the mandatory Section 7.3 sync protocol.Verified the guard is fully implemented and tested (no implementation work needed):
pkg/workflow/compiler_builtin_job_augmentation.go:guardIfAgainstStatusFuncBypass,ifExpressionContainsStatusFuncpkg/workflow/compiler_custom_jobs_test.go:TestApplyBuiltinJobNeedsAugmentations_StatusFuncAddsSuccessGuards,TestApplyBuiltinJobNeedsAugmentations_StatusFuncFailureAddsSuccessGuards,TestApplyBuiltinJobNeedsAugmentations_StatusFuncAlwaysAddsSuccessGuards,TestApplyBuiltinJobNeedsAugmentations_StatusFuncKeepsCustomJobUnguardedRule IDs
CTR-001mapping documentation reconciled.Files Changed
specs/compiler-threat-detection-spec.md:Tests Run
go.modrequiresgo 1.26.7; toolchain download blocked by network policy — environment limitation, not a code issue). No Go source was changed, so no test regressions are expected. Verified relevant guard tests already exist by direct source inspection (listed above).Note
No steering issue comments were available to review (steering issue number not provided in this run's context).
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
proxy.golang.orgTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
Warning
Firewall blocked 2 domains
The following domains were blocked by the firewall during workflow execution:
github.comregistry.npmjs.orgTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
Run: https://github.com/github/gh-aw/actions/runs/34015173514
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
$
Warning
Firewall blocked 2 domains
The following domains were blocked by the firewall during workflow execution:
github.comregistry.npmjs.orgTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.