Skip to content

fix(security): close remaining SBOM verification gaps - #336

Merged
hyochan merged 1 commit into
mainfrom
fix/sbom-323-complete-support
Aug 13, 2026
Merged

hyochan merged 1 commit into
mainfrom
fix/sbom-323-complete-support

Conversation

@hyochan

@hyochan hyochan commented Aug 13, 2026

Copy link
Copy Markdown
Member

Summary

Refs #323

Why this follow-up is needed

Post-merge verification found one legacy React Native asset that predates the generator-commit field, plus fail-open paths where an existing or concurrently replaced asset could be preserved without proving it came from the exact main workflow. This PR fills those remaining gaps instead of broadening the repair scope.

Changes

Published asset verification

  • Add a reusable verifier for release identity, release commit, generator commit, GitHub SHA-256 digest, CycloneDX structure, dependency reachability, and path/secret leakage.
  • Require the exact sbom.yml@refs/heads/main certificate identity and a GitHub-hosted runner.
  • Restrict publication to workflow_dispatch runs on the repository default branch and remove the incompatible release-event lane.

Guarded recovery

  • Add the exact legacy digest for react-native-iap-16.3.0 alongside the existing Google 3.3.0 repair guard.
  • Verify a non-legacy canonical asset before cleaning any staged replacement.
  • Retain the staged marker when the canonical asset changes during repair so the next main-branch run must reconcile it instead of silently preserving unverified state.

Audit and documentation

  • Audit every newest component SBOM with fail-fast content, digest, schema, and provenance checks.
  • Document exact-main workflow verification in the repository and docs site.

Verification

  • 78 release, provenance, SBOM, and security automation tests
  • 45 documentation audit tests
  • bun run audit:docs
  • bun run audit:parity
  • bun run audit:release-state
  • Docs typecheck, lint, format check, and production build
  • actionlint .github/workflows/sbom.yml
  • Prettier and git diff --check
  • Production docs bundle renders the exact-main attestation command with no new console errors
  • Fresh public release scan selects only react-native-iap-16.3.0 for the guarded repair

Preview

The rendered SBOM documentation preview is attached in the PR conversation.

@hyochan hyochan added 💨 ci Cloud integration 📖 documentation Improvements or additions to documentation 🛠 bugfix All kinds of bug fixes labels Aug 13, 2026
@hyochan

hyochan commented Aug 13, 2026

Copy link
Copy Markdown
Member Author

Preview

Rendered production documentation showing the exact-main attestation command:

sbom-preview.mp4

Repair the React Native 16.3.0 SBOM only when its exact legacy digest is present.

Verify existing assets against release identity, the GitHub digest, and exact main-workflow provenance before preserving them. Keep staged repair markers across races and align the public verification guidance.
@hyochan
hyochan force-pushed the fix/sbom-323-complete-support branch from c01c747 to 247e920 Compare August 13, 2026 16:41
@hyodotdev hyodotdev deleted a comment from coderabbitai Bot Aug 13, 2026
@hyochan
hyochan merged commit 66e3055 into main Aug 13, 2026
12 checks passed
@hyochan
hyochan deleted the fix/sbom-323-complete-support branch August 13, 2026 16:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🛠 bugfix All kinds of bug fixes 💨 ci Cloud integration 📖 documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant