-
Notifications
You must be signed in to change notification settings - Fork 6
[MINOR] chore: merge develop to main #78
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
44 commits
Select commit
Hold shift + click to select a range
7ac3398
apply dependabot insights
alain-sv 22d50aa
minor
alain-sv 2a89660
chore(ci): SHA-pin actions/checkout and actions/setup-python (#43)
alain-sv 297d98e
docs(changelog): add unreleased dependency security refresh entry (#44)
alain-sv 1c41f54
chore(ci): add uv cache-suffix per Python version + update AGENTS.md …
alain-sv 00aad5e
Merge branch 'main' into develop
alain-sv 1f5c176
supervaizer-v2-mvp-contracts (#47)
alain-sv d7c98b9
Minor
alain-sv b192229
Merge branch 'main' into develop
alain-sv 789b0c6
chore: update changelog for Supervaizer v2 enhancements and API key v…
alain-sv da4b00d
Merge branch 'main' into develop
alain-sv c977b6e
workspace-agent-grants (#50)
alain-sv a12b628
minor
alain-sv a761421
Merge branch 'main' into develop
alain-sv 1f20b22
feat(logging): implement structured logging for Cloud Logging compati…
alain-sv 746a04f
Merge branch 'main' into develop
alain-sv 75a3a0d
Minor
alain-sv 612001f
Merge branch 'main' into develop
alain-sv 3324db5
codex/supervaizer-lifespan-cleanup (#54)
alain-sv e7834a2
codex/refactor-server-modules (#55)
alain-sv 4fed877
minor
alain-sv afaf602
codex/agent-interviewer-workspace-jobs-refresh (#56)
alain-sv ceede13
Refactor pre-commit configuration and enhance agent validation
alain-sv 62f299d
Merge branch 'main' into develop
alain-sv ea6ce6c
chore(deps): bump uv from 0.11.14 to 0.11.15 (#58)
dependabot[bot] 770a668
chore(deps): bump starlette from 0.50.0 to 1.0.1 (#60)
dependabot[bot] 15e586e
chore(deps): bump trufflesecurity/trufflehog from 3.95.3 to 3.95.5 (#61)
dependabot[bot] 4d5703a
feat(.agents): add skill symlinks from runwaize skills cookbook
alain-sv f197480
chore(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#62)
dependabot[bot] b50b3e9
chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#63)
dependabot[bot] 4461b3e
chore(deps): bump starlette from 1.0.1 to 1.3.1 (#66)
dependabot[bot] 287b498
chore(deps): bump cryptography from 48.0.0 to 48.0.1 (#67)
dependabot[bot] d3dcc08
chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#68)
dependabot[bot] 5712dfd
chore(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1 (#69)
dependabot[bot] b64d982
chore(deps): bump trufflesecurity/trufflehog from 3.95.5 to 3.95.6 (#70)
dependabot[bot] dbd4e3f
codex/managed-context-sdk (#65)
alain-sv 665ef50
✨ feat(contracts): add V2ContextAssignment for context.assign (#71)
alain-sv ec535d1
feat: bump version to1.3.0 and update deps; iterate nested (#73)
alain-sv 4e8fc0f
changelog
alain-sv a09ef1a
chore(deps): bump actions/setup-python from 6.2.0 to 6.3.0 (#75)
dependabot[bot] 6a53535
chore(deps): bump trufflesecurity/trufflehog from 3.95.6 to 3.95.7 (#76)
dependabot[bot] 9bf38b0
Merge branch 'main' into develop
alain-sv fe1d11d
security: review summary (redacted) + safe P0/P1 hardening (#77)
alain-sv 5fe47c6
[MINOR] chore: merge develop to main
alain-sv File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,86 @@ | ||
| # Supervaizer — Security & Performance Review (Summary) | ||
|
|
||
| > **Date:** 2026-07-07 | ||
| > **Scope:** Full (non-diff) review of the entire `supervaizer` SDK source tree (~20k LOC). | ||
| > **Type:** Security review + performance/scalability review. | ||
| > | ||
| > **⚠️ Disclosure note:** Per [`SECURITY.md`](../SECURITY.md), detailed vulnerability | ||
| > findings — attack scenarios, exact code locations, and remediation specifics — are **not** | ||
| > published here. This page is a non-actionable high-level summary only. The complete | ||
| > findings are handled through the project's private vulnerability channel (GitHub Security | ||
| > Advisories) so that unpatched issues are not operationalized in a public artifact. | ||
|
|
||
| --- | ||
|
|
||
| ## Methodology | ||
|
|
||
| A multi-agent audit: per-component security finders reviewed the full source; every | ||
| high-impact candidate was independently re-checked by an adversarial verifier (instructed | ||
| to refute it and confirm real reachability), which recalibrated several severities; a | ||
| completeness critic then swept for missed classes; and a separate pass covered async | ||
| performance and scalability. This was a static review — no exploit was executed. | ||
|
|
||
| ## Overall posture | ||
|
|
||
| The **core authorization primitives are sound.** Verified during the review: | ||
|
|
||
| - Signed workspace authorization uses EdDSA with the algorithm pinned (no `alg:none` or | ||
| algorithm-confusion), full claim binding (issuer/audience/expiry/subject/workspace), and | ||
| keys sourced only from configured trust material. | ||
| - Privileged protocol actions fail **closed** when authorization is not configured. | ||
| - No SQL/NoSQL/command injection, no server-side template injection, and no unsafe | ||
| deserialization (`pickle`/`yaml.load`/`eval`) were found. | ||
| - No CORS misconfiguration — none is configured, so the safe same-origin default applies. | ||
| - Jinja autoescaping is enabled. | ||
|
|
||
| The material risk is concentrated in **credential handling and the trust model of the | ||
| administrative surface**, not in the request-validation core. Themes (no specifics here): | ||
|
|
||
| - Development/quick-start defaults that are unsafe if exposed on an untrusted network. | ||
| - An administrative surface whose trust boundary can be weakened under certain | ||
| reverse-proxy configurations. | ||
| - Credential material that is more exposed at rest / in transit than it should be. | ||
| - A symmetric-encryption construction that should be migrated to an authenticated (AEAD) | ||
| scheme. | ||
| - Deployment tooling that handles secrets less defensively than the runtime does. | ||
|
|
||
| ## Supply-chain posture (already in place) | ||
|
|
||
| The repository already implements a strong supply-chain baseline, documented in | ||
| [`SECURITY.md`](../SECURITY.md): a committed `uv.lock` with `uv sync --frozen` enforced in | ||
| CI, Dependabot security updates, OSV-Scanner on every PR, secret scanning with push | ||
| protection, SHA-pinned third-party Actions, and OIDC Trusted Publishing. Pinned dependency | ||
| floors were reviewed and are modern (no known-vulnerable pins). **No supply-chain action is | ||
| recommended beyond what already exists.** | ||
|
|
||
| ## Findings summary (counts only) | ||
|
|
||
| | Domain | Critical | High | Medium | Low | | ||
| |--------|----------|------|--------|-----| | ||
| | Security (post-verification) | 0 | 6 | 16 | 18 | | ||
| | Performance / scalability | — | 9 | 10 | 2 | | ||
|
|
||
| No finding survived verification at **Critical**. | ||
|
|
||
| ### Performance themes | ||
|
|
||
| The performance findings cluster into two areas: **unbounded in-memory growth** (long-lived | ||
| registries that do not evict completed work) and **event-loop blocking** (synchronous I/O | ||
| and whole-file persistence operations executed on the async loop). Neither is a correctness | ||
| bug today; each degrades under sustained load or data growth. The highest-leverage | ||
| mitigations are caching/offloading the persistence layer, evicting terminal entities, and | ||
| using the already-present async code paths for request-time verification. | ||
|
|
||
| ## Remediation approach | ||
|
|
||
| Detailed, prioritized remediation guidance (P0–P3) accompanies the private report. At a | ||
| high level: address credential-handling and admin-trust items first, migrate the symmetric | ||
| encryption to an AEAD construction, then harden response headers, request limits, and | ||
| object-level authorization, and finally apply the performance mitigations. The core | ||
| architecture does not require redesign. | ||
|
|
||
| --- | ||
|
|
||
| *For the complete findings and remediation detail, maintainers should refer to the private | ||
| security advisory. Report any deviation from the documented security posture via the private | ||
| channel in [`SECURITY.md`](../SECURITY.md).* |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When a local dev server needs to be reachable outside the host, e.g.
supervaizer start --local --host 0.0.0.0in Docker, this branch rewrites that explicit value to127.0.0.1before constructing or overriding theServer, so uvicorn still binds only loopback even though the release note says an explicit--hostcan override the safer default. Track whether the option was actually omitted, and only rewrite the default wildcard binding.Useful? React with 👍 / 👎.