fix(security): make the SBOM workflow able to describe any release tag - #319
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (10)
📝 WalkthroughWalkthroughThe SBOM generator now separates release and generator commits, validates release tags, and records generator metadata. The workflow uses current generator scripts with released dependency manifests. Documentation and tests cover core inventory reproducibility and variable registry metadata. ChangesSBOM generation policy
Estimated code review effort: 3 (Moderate) | ~25 minutes Mergeability Score: ⚪ Minimal · up to This PR updates SBOM generation for historical release tags and aligns the documentation with the workflow's behavior; no actionable merge-blocking risk remains after normal checks and review. Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/sbom.yml:
- Around line 58-75: Make SBOM generation inputs explicit: in
.github/workflows/sbom.yml lines 58-75, capture the full generator commit SHA
from FETCH_HEAD and persist it in the generated SBOM or attestation; in
security/SBOM.md lines 318-323, update the byte-identical reproduction claim to
account for the mutable generator revision and live registry metadata, or
document the frozen registry metadata required for exact reproduction.
- Around line 58-75: Add a historical-release compatibility audit for the
mixed-tree workflow where the default-branch scripts are checked out by the
generator step. Create representative historical manifest/tag-alias fixtures or
golden assertions and extend scripts/generate-sbom.test.mjs to verify dependency
completeness and successful SBOM generation for those releases, including cases
that could otherwise skip or fail due to older formats.
In `@security/SBOM.md`:
- Around line 318-323: Remove the --clobber option from the workflow_dispatch
release-asset upload so existing assets cannot be overwritten. Update the SBOM
reproduction policy to state that byte-identical output is not guaranteed when
--with-licenses retrieves live registry metadata, since registry failures can
alter license and supplier fields.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 65bd7b17-0dd8-4487-8f24-970bb1b03d94
📒 Files selected for processing (2)
.github/workflows/sbom.ymlsecurity/SBOM.md
PreviewSBOM documentation now distinguishes the reproducible core inventory from point-in-time registry metadata and records the exact generator commit. pr319-sbom-preview.mp4 |
## Summary - Move the 19 tracked PR preview assets to GitHub user attachments in their original PR bodies or comments. - Remove `.github/pr-previews` from version control. - Require temporary local recordings and direct GitHub uploads; blocked uploads now stop for permission instead of force-adding a Git fallback. ## Verification - All 20 migrated attachments, including PR #319, return the expected media type through ranged HTTP requests. - All 22 affected PR body/comment locations reference their new `user-attachments` URLs. - `bun audit:docs` - `bun audit:parity` - `bun run audit:release-state` - Prettier check for the edited source guidance - `git diff --check` ## Preview Not applicable: this removes repository-only review media and changes internal contribution guidance. The attachment and reference checks above are the relevant proof. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated preview-sharing guidance to require temporary recordings to be uploaded as attachments and deleted afterward. * Prohibited committing one-off preview recordings as fallback assets. * Added instructions to stop and request maintainer assistance when attachment uploads are unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Dispatching sbom.yml against react-native-iap-16.3.0 failed with MODULE_NOT_FOUND: the workflow checks out the release tag, and that commit predates the generator. The generator is a tool and the tag is its input, so pinning the tool to whatever sat in the tagged commit was wrong in both directions — a tag older than the generator could not be described at all, and a generator fix would never reach a regenerated SBOM. The workflow now restores just the generator scripts from the default branch. Every dependency manifest it reads still comes from the released commit. security/SBOM.md promised retroactive generation that could not work; the update policy now describes what actually happens.
The generator's tests validate the tree that owns them, so pointing them at a released commit fails on any tag from before a component existed — react-native-iap-16.3.0 predates packages/conformance. They already run in ci.yml on every pull request, where the target is correct. The guard that matters is the next step, which verifies the produced document: version, tag, and commit must agree, and no local path may appear.
eb25971 to
003763d
Compare
Summary
Dispatching
sbom.ymlfor the first time — against the realreact-native-iap-16.3.0release — failed. Two defects, both found by actually running it.What was wrong
1. The generator was taken from the released commit.
The workflow checks out the release tag, and that commit predates the generator. This was wrong in both directions: a tag older than the generator could not be described at all, and a generator fix would never reach a regenerated SBOM.
The generator is a tool; the tag is its input. The workflow now restores just the generator scripts from the default branch. Every dependency manifest it reads still comes from the released commit, so the SBOM still describes the release rather than
main.2. The generator's tests ran against the released tree.
react-native-iap-16.3.0predatespackages/conformance, so tests that iterate every releasable component failed on a manifest that was never there. Those tests validate the tree that owns them and already run inci.ymlon every pull request, where the target is correct. Removed from this workflow.The guard that matters is the step after it, which verifies the produced document: version, tag, and commit must agree, and no local path may appear.
Verified end to end
Dispatched from this branch against the real release. All steps pass, and the artifact is now attached to
react-native-iap-16.3.0:cyclonedx validate --input-version v1_6→ BOM validated successfullygh attestation verify --repo hyodotdev/openiap→ exit 0, SLSA v1 predicate, subject digest matches, signed bytoken.actions.githubusercontent.com, builder.github/workflows/sbom.ymlsecurity/SBOM.mdpromised retroactive generation that could not work; the update policy now describes what actually happens.Test plan
bun audit:docsclean🤖 Generated with Claude Code
Summary by CodeRabbit