From 8e0e17d2178df0a0f62f164a65c9cc86c32bda63 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 18 Jun 2026 15:07:15 -0400 Subject: [PATCH] fix(secrev): hide dependency-cve canary manifests from dependency-review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The canary fixtures intentionally pin known-vulnerable deps (jinja2 2.11.2, lodash 4.17.15) so the checker has something to detect. GitHub's dependency graph parsed those fixture manifests as real project deps, failing the dependency-review PR gate (fail-on-severity: high). Store the manifests with a .fixture suffix so the dependency graph ignores them; the --canary materializer strips the suffix in its temp work area before scanning, so detection is unchanged (still 2/2). No advisory allowlist, no change to the shared org reusable workflow — the real gate stays strict for actual deps. --- security-review/checkers/dependency-cve.sh | 8 ++++++++ .../checkers/fixtures/dependency-cve/README.md | 8 ++++++++ .../{requirements.txt => requirements.txt.fixture} | 0 .../{package-lock.json => package-lock.json.fixture} | 0 .../{requirements.txt => requirements.txt.fixture} | 0 5 files changed, 16 insertions(+) rename security-review/checkers/fixtures/dependency-cve/clean-repo/{requirements.txt => requirements.txt.fixture} (100%) rename security-review/checkers/fixtures/dependency-cve/vuln-js-repo/{package-lock.json => package-lock.json.fixture} (100%) rename security-review/checkers/fixtures/dependency-cve/vuln-py-repo/{requirements.txt => requirements.txt.fixture} (100%) diff --git a/security-review/checkers/dependency-cve.sh b/security-review/checkers/dependency-cve.sh index 2e38541..8a2a35c 100755 --- a/security-review/checkers/dependency-cve.sh +++ b/security-review/checkers/dependency-cve.sh @@ -354,6 +354,14 @@ if [ "$CANARY" -eq 1 ]; then nm="$(basename "$d")" cp -R "$d" "$FIXTURE_WORK/$nm" mv "$FIXTURE_WORK/$nm/dotgit" "$FIXTURE_WORK/$nm/.git" + # Manifests are stored as .fixture so GitHub's dependency graph / the + # dependency-review CI action does NOT parse the deliberately-vulnerable canary + # pins as real project dependencies. Restore their real names in the materialized + # work area so the checker's per-ecosystem parsers dispatch correctly (same + # committable-without-side-effects rationale as the dotgit/ rename above). + while IFS= read -r ff; do + [ -n "$ff" ] && mv "$ff" "${ff%.fixture}" + done < <(find "$FIXTURE_WORK/$nm" -name '*.fixture' -not -path '*/.git/*' 2>/dev/null) REPO_NAMES+=( "$nm" ); REPO_DIR["$nm"]="$FIXTURE_WORK/$nm" done elif [ -n "$TARGETS_OVERRIDE" ]; then diff --git a/security-review/checkers/fixtures/dependency-cve/README.md b/security-review/checkers/fixtures/dependency-cve/README.md index 20dabb1..54d8822 100644 --- a/security-review/checkers/fixtures/dependency-cve/README.md +++ b/security-review/checkers/fixtures/dependency-cve/README.md @@ -32,3 +32,11 @@ regression in either parser is caught. When you add/remove a parser, a fixture, or an advisory entry, update the fixture(s), `osv-advisories.json`, and `EXPECTED_VULN_COUNT` in the same commit (the canary edit is itself caught on the next run — design §6.4). + +**Manifest naming:** the dependency manifests are stored with a `.fixture` suffix +(`requirements.txt.fixture`, `package-lock.json.fixture`) so GitHub's dependency graph / +the `dependency-review` CI action does NOT parse the deliberately-vulnerable canary pins as +real project dependencies (which would fail the PR gate). The checker's `--canary` +materialization strips the `.fixture` suffix in its temp work area before scanning, so the +per-ecosystem parsers still dispatch on the real names. Keep this suffix on any new +manifest fixture. diff --git a/security-review/checkers/fixtures/dependency-cve/clean-repo/requirements.txt b/security-review/checkers/fixtures/dependency-cve/clean-repo/requirements.txt.fixture similarity index 100% rename from security-review/checkers/fixtures/dependency-cve/clean-repo/requirements.txt rename to security-review/checkers/fixtures/dependency-cve/clean-repo/requirements.txt.fixture diff --git a/security-review/checkers/fixtures/dependency-cve/vuln-js-repo/package-lock.json b/security-review/checkers/fixtures/dependency-cve/vuln-js-repo/package-lock.json.fixture similarity index 100% rename from security-review/checkers/fixtures/dependency-cve/vuln-js-repo/package-lock.json rename to security-review/checkers/fixtures/dependency-cve/vuln-js-repo/package-lock.json.fixture diff --git a/security-review/checkers/fixtures/dependency-cve/vuln-py-repo/requirements.txt b/security-review/checkers/fixtures/dependency-cve/vuln-py-repo/requirements.txt.fixture similarity index 100% rename from security-review/checkers/fixtures/dependency-cve/vuln-py-repo/requirements.txt rename to security-review/checkers/fixtures/dependency-cve/vuln-py-repo/requirements.txt.fixture