SECURITY: update locked JavaScript packages with known advisories #810

Open
opened 2026-10-02 13:13:03 +00:00 by kayg · 9 comments
Owner

Context

Read-only supply-chain audit assigned under #663, base origin/dev c4a61e8cf0. bun audit --json exited 1 on 2026-10-02. Duplicate searches for tiptap, PDF.js, dependency, audit and supply chain found no issue for these advisory updates.

Evidence and impact

  • apps/web/package.json:79 and packages/editor/package.json:56 select @tiptap/core 3.27.1. GHSA-cp6q-959q-f8rh is fixed in 3.30.4; GHSA-j95f-988m-3j2f is fixed in 3.30.5. packages/editor/src/image.ts:92 and callout.ts:42 use mergeAttributes with declared schema attributes. The app uses its own Markdown converter, not the affected Tiptap Markdown helpers. No hostile arbitrary attribute boundary was proved.
  • packages/ui/package.json:28 locks pdfjs-dist 5.7.284, affected by GHSA-hq66-cqwq-w95j; fixed in 6.2.108. packages/ui/src/components/viewer/PdfView.svelte:36 opens PDFs with the default options. The production shell enforces script-src with no unsafe-inline/unsafe-eval (crates/calternal-server/src/security.rs:121), which upstream lists as a mitigation. This is dependency debt, not a proved production script-execution hole. The canvas-only viewer does not instantiate PDFScriptingManager.
  • apps/web/package.json selects sharp ^0.34.2; the lock has 0.34.5. GHSA-f88m-g3jw-g9cj and GHSA-rgj7-g3m4-5g8c are fixed by 0.35.4 or later. The repo calls sharp only from developer icon/contact-sheet scripts, not a server upload route.
  • bun.lock has @sveltejs/kit/cookie 0.6.0, affected by GHSA-pxg6-pf52-xh8x (<0.7.0). The root cookie 2.0.1 is not affected. The shipped adapter-static SPA does not run SvelteKit's Node server.

Registry versions verified on 2026-10-02: Tiptap 3.31.4, PDF.js 6.3.289, sharp 0.35.5, SvelteKit 3.0.0. These are evidence, not permission for an unrelated major migration.

Concrete fix

Upgrade the Tiptap package family together to a reviewed release >=3.30.5; upgrade PDF.js >=6.2.108 and its worker together; upgrade sharp >=0.35.4. Remove the vulnerable nested cookie through a compatible upstream SvelteKit release or a reviewed scoped override. Update the Bun lock. Explicitly disable PDF scripting through the supported viewer integration if it is added later. Keep enforced CSP.

Validation

Run bun audit against the final frozen lock and require these advisory IDs to be absent. Run web check/test and editor tests; check PDF rendering and clipboard/HTML export on a production build. Add a benign test that exported schema attributes stay on an ordinary object and cannot create inherited DOM attributes. Verify CSP remains enforced and the PDF worker uses the same version. No exploit payload is required.

Primary sources

Non-blocking under CLAUDE.md: version matches are confirmed; a product security hole was not proved.

## Context Read-only supply-chain audit assigned under #663, base origin/dev c4a61e8cf090170f35b1bed3350d9de20c83ecd5. `bun audit --json` exited 1 on 2026-10-02. Duplicate searches for tiptap, PDF.js, dependency, audit and supply chain found no issue for these advisory updates. ## Evidence and impact - `apps/web/package.json:79` and `packages/editor/package.json:56` select @tiptap/core 3.27.1. GHSA-cp6q-959q-f8rh is fixed in 3.30.4; GHSA-j95f-988m-3j2f is fixed in 3.30.5. `packages/editor/src/image.ts:92` and `callout.ts:42` use mergeAttributes with declared schema attributes. The app uses its own Markdown converter, not the affected Tiptap Markdown helpers. No hostile arbitrary attribute boundary was proved. - `packages/ui/package.json:28` locks pdfjs-dist 5.7.284, affected by GHSA-hq66-cqwq-w95j; fixed in 6.2.108. `packages/ui/src/components/viewer/PdfView.svelte:36` opens PDFs with the default options. The production shell enforces script-src with no unsafe-inline/unsafe-eval (`crates/calternal-server/src/security.rs:121`), which upstream lists as a mitigation. This is dependency debt, not a proved production script-execution hole. The canvas-only viewer does not instantiate PDFScriptingManager. - `apps/web/package.json` selects sharp ^0.34.2; the lock has 0.34.5. GHSA-f88m-g3jw-g9cj and GHSA-rgj7-g3m4-5g8c are fixed by 0.35.4 or later. The repo calls sharp only from developer icon/contact-sheet scripts, not a server upload route. - `bun.lock` has @sveltejs/kit/cookie 0.6.0, affected by GHSA-pxg6-pf52-xh8x (<0.7.0). The root cookie 2.0.1 is not affected. The shipped adapter-static SPA does not run SvelteKit's Node server. Registry versions verified on 2026-10-02: Tiptap 3.31.4, PDF.js 6.3.289, sharp 0.35.5, SvelteKit 3.0.0. These are evidence, not permission for an unrelated major migration. ## Concrete fix Upgrade the Tiptap package family together to a reviewed release >=3.30.5; upgrade PDF.js >=6.2.108 and its worker together; upgrade sharp >=0.35.4. Remove the vulnerable nested cookie through a compatible upstream SvelteKit release or a reviewed scoped override. Update the Bun lock. Explicitly disable PDF scripting through the supported viewer integration if it is added later. Keep enforced CSP. ## Validation Run bun audit against the final frozen lock and require these advisory IDs to be absent. Run web check/test and editor tests; check PDF rendering and clipboard/HTML export on a production build. Add a benign test that exported schema attributes stay on an ordinary object and cannot create inherited DOM attributes. Verify CSP remains enforced and the PDF worker uses the same version. No exploit payload is required. ## Primary sources - https://github.com/ueberdosis/tiptap/security/advisories/GHSA-cp6q-959q-f8rh - https://github.com/ueberdosis/tiptap/security/advisories/GHSA-j95f-988m-3j2f - https://github.com/mozilla/pdf.js/security/advisories/GHSA-hq66-cqwq-w95j - https://github.com/lovell/sharp/security/advisories/GHSA-f88m-g3jw-g9cj - https://github.com/lovell/sharp/security/advisories/GHSA-rgj7-g3m4-5g8c Non-blocking under CLAUDE.md: version matches are confirmed; a product security hole was not proved.
Author
Owner

Starting #810 on branch job/deps, based at 2f4482ded066d9c5d9c59130377907f7fd2916c9 (job/merge-round-7a). I read the issue, audit evidence, CLAUDE.md, CONTEXT.md and relevant DESIGN sections. I will verify patched package versions, update the lock, and add the requested regression and compatibility checks.

Starting #810 on branch `job/deps`, based at `2f4482ded066d9c5d9c59130377907f7fd2916c9` (`job/merge-round-7a`). I read the issue, audit evidence, CLAUDE.md, CONTEXT.md and relevant DESIGN sections. I will verify patched package versions, update the lock, and add the requested regression and compatibility checks.
Author
Owner

Evidence update: a single JSON-origin attribute object with an own __proto__ key reproduces the Tiptap merge behavior. The new benign regression test failed against locked @tiptap/core@3.27.1: DOMSerializer.renderSpec copied inherited onerror and src attributes from the merge result. The same test passes after moving the Tiptap family to 3.31.4. Registry metadata confirms Tiptap 3.31.4, PDF.js 6.3.289, sharp 0.35.5 and cookie 0.7.2. SvelteKit's latest v2 release still declares cookie ^0.6.0, so the fix uses Bun's package-scoped @sveltejs/kit>cookie override and leaves root cookie 2.x unchanged.

Evidence update: a single JSON-origin attribute object with an own `__proto__` key reproduces the Tiptap merge behavior. The new benign regression test failed against locked `@tiptap/core@3.27.1`: `DOMSerializer.renderSpec` copied inherited `onerror` and `src` attributes from the merge result. The same test passes after moving the Tiptap family to 3.31.4. Registry metadata confirms Tiptap 3.31.4, PDF.js 6.3.289, sharp 0.35.5 and cookie 0.7.2. SvelteKit's latest v2 release still declares cookie `^0.6.0`, so the fix uses Bun's package-scoped `@sveltejs/kit>cookie` override and leaves root cookie 2.x unchanged.
Author
Owner

Update: after PDF.js 6.3.289, apps/web bun run check reports two type errors in packages/ui/src/components/viewer/PdfView.svelte (lines 39 and 100): PDFDocumentProxy.destroy() no longer exists. PDF.js v6.3.289 release notes confirm its removal. I am adding a regression for destroying the active PDFDocumentLoadingTask when the view unmounts or changes source. The first focused Vitest attempt failed before test collection because the worker did not start before its timeout; it did not produce an assertion result.

Update: after PDF.js 6.3.289, `apps/web bun run check` reports two type errors in `packages/ui/src/components/viewer/PdfView.svelte` (lines 39 and 100): `PDFDocumentProxy.destroy()` no longer exists. PDF.js v6.3.289 release notes confirm its removal. I am adding a regression for destroying the active `PDFDocumentLoadingTask` when the view unmounts or changes source. The first focused Vitest attempt failed before test collection because the worker did not start before its timeout; it did not produce an assertion result.
Author
Owner

Update: the new PdfView lifecycle regression failed on the previous code with expected vi.fn() to be called once, but got 0 times. After the fix, the focused component test passes (Test Files 1 passed, Tests 1 passed). The fix tracks the PDF.js loading task and destroys it when loading is replaced, fails, or the view unmounts. I am rerunning the full web check now.

Update: the new `PdfView` lifecycle regression failed on the previous code with `expected vi.fn() to be called once, but got 0 times`. After the fix, the focused component test passes (`Test Files 1 passed`, `Tests 1 passed`). The fix tracks the PDF.js loading task and destroys it when loading is replaced, fails, or the view unmounts. I am rerunning the full web check now.
Author
Owner

Completed on branch job/deps. Final head: 306fd0a953.

Updated Tiptap to 3.31.4 (kept @tiptap/y-tiptap at 3.0.5), PDF.js to 6.3.289, sharp to 0.35.5, and the scoped SvelteKit cookie override to 0.7.2. Fixed PDF cleanup to destroy the PDFDocumentLoadingTask on source change, load failure, or unmount. The new lifecycle test failed before the fix because destroy was not called, then passed.

Gate output:

svelte-check found 0 errors and 0 warnings
Test Files  155 passed (155)
Tests  1074 passed (1074)
✓ built in 1m 1s
  Wrote site to "build"
  ✔ done

UX gaps closed: a closed or replaced PDF view now cancels its active worker and network task. UX gaps left: real-server PDF Quick Look and clipboard/HTML export E2E were not run. The existing PDF text layer is still not selectable.

Known gate gap: cargo test -p calternal-search was stopped at the four-hour timebox while compiling; it exited 130 without a test summary. calternal-auth tests and clippy were not run.

Decisions: kept y-tiptap 3.0.5 because 3.0.7 and 3.0.9 broke the mixed-paste undo/redo regression. PDF.js v6 removed PDFDocumentProxy.destroy(), so cleanup now follows the v6 task API (release notes, loading-task API).

Completed on branch job/deps. Final head: 306fd0a953f342395af64cc62f0b18f3416ea95a. Updated Tiptap to 3.31.4 (kept @tiptap/y-tiptap at 3.0.5), PDF.js to 6.3.289, sharp to 0.35.5, and the scoped SvelteKit cookie override to 0.7.2. Fixed PDF cleanup to destroy the PDFDocumentLoadingTask on source change, load failure, or unmount. The new lifecycle test failed before the fix because destroy was not called, then passed. Gate output: ``` svelte-check found 0 errors and 0 warnings Test Files 155 passed (155) Tests 1074 passed (1074) ✓ built in 1m 1s Wrote site to "build" ✔ done ``` UX gaps closed: a closed or replaced PDF view now cancels its active worker and network task. UX gaps left: real-server PDF Quick Look and clipboard/HTML export E2E were not run. The existing PDF text layer is still not selectable. Known gate gap: cargo test -p calternal-search was stopped at the four-hour timebox while compiling; it exited 130 without a test summary. calternal-auth tests and clippy were not run. Decisions: kept y-tiptap 3.0.5 because 3.0.7 and 3.0.9 broke the mixed-paste undo/redo regression. PDF.js v6 removed PDFDocumentProxy.destroy(), so cleanup now follows the v6 task API ([release notes](https://github.com/mozilla/pdf.js/releases/tag/v6.3.289), [loading-task API](https://mozilla.github.io/pdf.js/api/draft/module-pdfjsLib-PDFDocumentLoadingTask.html)).
Author
Owner

Read-only review started on job/rev2-deps, base 440e19dce2. Review target: job/deps at 306fd0a953. No builds, tests, installs, servers or browsers will run. The review will distinguish dependency changes from the imported merge-round changes.

Read-only review started on job/rev2-deps, base 440e19dce23040ac8ebaae88f0469b6535b1afcb. Review target: job/deps at 306fd0a953f342395af64cc62f0b18f3416ea95a. No builds, tests, installs, servers or browsers will run. The review will distinguish dependency changes from the imported merge-round changes.
Author
Owner

Read-only review of job/deps

Date: 2026-10-02. Owning issue: #810.
Reviewed head: 306fd0a953f342395af64cc62f0b18f3416ea95a.
Review branch: job/rev2-deps.
Base and merge base: 440e19dce23040ac8ebaae88f0469b6535b1afcb.

Result

One P1 and two P2 findings remain. No P3 finding is raised.
Do not treat the dependency branch as ready for release until the CA
bootstrap order is fixed and a clean container build confirms it.
No current incompatible package or model licence was proved.

Priority Evidence at reviewed head Required fix Existing issue
P1 deploy/Containerfile.runtime:12, :15, :133, :136; Containerfile:42; deploy/nested-podman/Containerfile:17 Install trusted CA certificates before the first HTTPS APT update in each slim stage. Keep dated snapshots and archive signature checks. #813
P2 scripts/refresh_dependency_license_inventory.py:57–:65 Read the licence from the checksum-verified crate archive, rather than unchecked extracted source. #812
P2 scripts/dependency_policy.py:526–:530; crates/calternal-embed/models/manifest.json:4, :34 Add model identities and reviewed licence evidence to the ongoing check required by #812. #812

audit-findings.md gives each finding's evidence, rule, expected behaviour
and test idea. Evidence was posted to #813 and #812 after duplicate searches.
No duplicate issue was created. No issue was closed.

The P1 is a static inference. The Debian slim package list has no CA package,
and APT uses system CAs for HTTPS verification. The changed stages install
that package after their first HTTPS update. A host HTTP 200 probe cannot
verify this stage's trust store. See the
Debian slim package list
and APT HTTPS documentation.

Coverage

Read CLAUDE.md, CONTEXT.md, DESIGN and issues #810–#813, including their
implementation reports. Inspect the requested origin/dev...HEAD diff and
the dependency commits separately from their imported merge-round changes.
The full diff contains 282 files. This review covers the dependency commits;
it is not an independent correctness review of every imported feature.

Reviewed changes include package versions and Bun resolution, four Cargo
lock changes, the licence inventory and refresh path, RustSec exception
handling, workflow and image pins, snapshot sources, PDF task ownership,
the HTML attribute regression, and policy fixtures.

The lock resolves the updated Tiptap family to 3.31.4, PDF.js to 6.3.289,
sharp to 0.35.5 and the nested SvelteKit cookie to 0.7.2. Root cookie stays
2.0.1. Upstream release pages confirm
Tiptap 3.31.4,
PDF.js 6.3.289,
and sharp 0.35.5.
The checked inventory declares MIT for Tiptap and cookie, and Apache-2.0
for PDF.js and sharp. These declared licences fit the project policy.
This review did not authenticate every distributed native dependency notice.

PDF.js and its worker come from the same package. The lifecycle fix uses the
loading task as resource owner and rejects stale loads with a token.
The focused regression covers unmount before load completion. It does not
cover source replacement, load failure or an active page render at teardown.
The enforced server CSP still excludes unsafe script evaluation.

PDF code remains loaded on first use. The policy checks run in CI, outside
interactive request paths. The existing full page-size scan still delays
first-page display; this is inherited behaviour, tracked by #805. No new
performance measurement was run in this read-only job.

The branch keeps y-tiptap 3.0.5 after newer versions failed its mixed-paste
undo test. The updated collaboration packages declare peer range ^3.0.7
in bun.lock:552 and :554. This is an acknowledged compatibility risk,
not a proved defect. Preserve the mixed-paste regression and test live
collaboration before the merge round completes.

Verification

No builds, tests, installs, servers, browsers, benchmarks or cleanup of
shared build output ran. The LIGHT job rule takes precedence over build
gates. No product code changed. No push, deploy or merge occurred.

Local document check: git diff --check exited 0 and wrote no output.
There is no build or test gate output from this review to quote.
The implementation issue contains earlier gate results; those results are
not independent verification by this job.

For the merge round

  • podman build --no-cache -f Containerfile .: prove the slim runtime can
    install its pinned packages after the CA fix.
  • podman build --no-cache --target codec-build -f deploy/Containerfile.runtime .:
    prove the codec stage can bootstrap its package index. Also run the existing
    complete runtime build with its real BINARY and AGENT_IMAGE_ARCHIVE
    arguments, and the nested-Podman image build. Repeat clean builds to compare
    resolved inputs, as #813 requires.
  • python3 -m unittest discover -s scripts -p 'test_dependency_policy.py' and
    python3 -m unittest discover -s scripts -p 'test_supply_chain_policy.py':
    run the existing and new provenance, model and CA-order fixtures.
  • python3 scripts/dependency_policy.py --check and
    python3 scripts/supply_chain_policy.py --check: check the combined branch's
    final lock, licence inventory and build inputs.
  • In apps/web, bun run check and
    bunx vitest run src/lib/components/PdfView.svelte.test.ts --maxWorkers=2:
    check PDF types and lifecycle behaviour. Extend the lifecycle test first
    for source replacement and load failure.
  • In packages/editor, bunx vitest run src/image.security.test.ts --maxWorkers=2:
    check benign HTML attribute export. Run the existing collaboration and
    mixed-paste undo suites as part of the merge round's full web tests.
  • Complete real production PDF rendering, clipboard/HTML export and live
    collaboration checks. Complete the Rust gates that the implementation
    report left open for calternal-auth and calternal-search.

Deliverables, gaps and decisions

Built: two review documents only, review-deps.md and audit-findings.md.
Known gaps: static evidence only; no clean image build; no runtime or visual
evidence; imported feature changes require their own reviews; native notices
were not exhaustively verified. No product fix was made.
UX gaps closed: none in this read-only job. UX gaps left: runtime PDF and
clipboard/export checks listed above; the existing non-selectable PDF text
layer remains outside this dependency fix.
Product decisions outside DESIGN: none. Review scope follows #810–#813 and
the LIGHT job rule. Use existing #812 and #813 as fix owners.

Review head SHA: 881b02465050976277990e516b5671731cdcfbb7.
Atomic review commits: 20ddab598, 310ed222d, 881b02465.
Gate output: no build or test gates ran under the LIGHT rule.
git diff --check exited 0 with no output; the working tree is clean.

# Read-only review of job/deps Date: 2026-10-02. Owning issue: #810. Reviewed head: `306fd0a953f342395af64cc62f0b18f3416ea95a`. Review branch: `job/rev2-deps`. Base and merge base: `440e19dce23040ac8ebaae88f0469b6535b1afcb`. ## Result One P1 and two P2 findings remain. No P3 finding is raised. Do not treat the dependency branch as ready for release until the CA bootstrap order is fixed and a clean container build confirms it. No current incompatible package or model licence was proved. | Priority | Evidence at reviewed head | Required fix | Existing issue | | --- | --- | --- | --- | | P1 | `deploy/Containerfile.runtime:12`, `:15`, `:133`, `:136`; `Containerfile:42`; `deploy/nested-podman/Containerfile:17` | Install trusted CA certificates before the first HTTPS APT update in each slim stage. Keep dated snapshots and archive signature checks. | #813 | | P2 | `scripts/refresh_dependency_license_inventory.py:57`–`:65` | Read the licence from the checksum-verified crate archive, rather than unchecked extracted source. | #812 | | P2 | `scripts/dependency_policy.py:526`–`:530`; `crates/calternal-embed/models/manifest.json:4`, `:34` | Add model identities and reviewed licence evidence to the ongoing check required by #812. | #812 | `audit-findings.md` gives each finding's evidence, rule, expected behaviour and test idea. Evidence was posted to #813 and #812 after duplicate searches. No duplicate issue was created. No issue was closed. The P1 is a static inference. The Debian slim package list has no CA package, and APT uses system CAs for HTTPS verification. The changed stages install that package after their first HTTPS update. A host HTTP 200 probe cannot verify this stage's trust store. See the [Debian slim package list](https://github.com/debuerreotype/docker-debian-artifacts/blob/dist-amd64/trixie/slim/rootfs.manifest) and [APT HTTPS documentation](https://manpages.debian.org/trixie/apt/apt-transport-https.1.en.html). ## Coverage Read CLAUDE.md, CONTEXT.md, DESIGN and issues #810–#813, including their implementation reports. Inspect the requested `origin/dev...HEAD` diff and the dependency commits separately from their imported merge-round changes. The full diff contains 282 files. This review covers the dependency commits; it is not an independent correctness review of every imported feature. Reviewed changes include package versions and Bun resolution, four Cargo lock changes, the licence inventory and refresh path, RustSec exception handling, workflow and image pins, snapshot sources, PDF task ownership, the HTML attribute regression, and policy fixtures. The lock resolves the updated Tiptap family to 3.31.4, PDF.js to 6.3.289, sharp to 0.35.5 and the nested SvelteKit cookie to 0.7.2. Root cookie stays 2.0.1. Upstream release pages confirm [Tiptap 3.31.4](https://github.com/ueberdosis/tiptap/releases/tag/v3.31.4), [PDF.js 6.3.289](https://github.com/mozilla/pdf.js/releases/tag/v6.3.289), and [sharp 0.35.5](https://github.com/lovell/sharp/releases/tag/v0.35.5). The checked inventory declares MIT for Tiptap and cookie, and Apache-2.0 for PDF.js and sharp. These declared licences fit the project policy. This review did not authenticate every distributed native dependency notice. PDF.js and its worker come from the same package. The lifecycle fix uses the loading task as resource owner and rejects stale loads with a token. The focused regression covers unmount before load completion. It does not cover source replacement, load failure or an active page render at teardown. The enforced server CSP still excludes unsafe script evaluation. PDF code remains loaded on first use. The policy checks run in CI, outside interactive request paths. The existing full page-size scan still delays first-page display; this is inherited behaviour, tracked by #805. No new performance measurement was run in this read-only job. The branch keeps y-tiptap 3.0.5 after newer versions failed its mixed-paste undo test. The updated collaboration packages declare peer range `^3.0.7` in `bun.lock:552` and `:554`. This is an acknowledged compatibility risk, not a proved defect. Preserve the mixed-paste regression and test live collaboration before the merge round completes. ## Verification No builds, tests, installs, servers, browsers, benchmarks or cleanup of shared build output ran. The LIGHT job rule takes precedence over build gates. No product code changed. No push, deploy or merge occurred. Local document check: `git diff --check` exited 0 and wrote no output. There is no build or test gate output from this review to quote. The implementation issue contains earlier gate results; those results are not independent verification by this job. ## For the merge round - `podman build --no-cache -f Containerfile .`: prove the slim runtime can install its pinned packages after the CA fix. - `podman build --no-cache --target codec-build -f deploy/Containerfile.runtime .`: prove the codec stage can bootstrap its package index. Also run the existing complete runtime build with its real `BINARY` and `AGENT_IMAGE_ARCHIVE` arguments, and the nested-Podman image build. Repeat clean builds to compare resolved inputs, as #813 requires. - `python3 -m unittest discover -s scripts -p 'test_dependency_policy.py'` and `python3 -m unittest discover -s scripts -p 'test_supply_chain_policy.py'`: run the existing and new provenance, model and CA-order fixtures. - `python3 scripts/dependency_policy.py --check` and `python3 scripts/supply_chain_policy.py --check`: check the combined branch's final lock, licence inventory and build inputs. - In `apps/web`, `bun run check` and `bunx vitest run src/lib/components/PdfView.svelte.test.ts --maxWorkers=2`: check PDF types and lifecycle behaviour. Extend the lifecycle test first for source replacement and load failure. - In `packages/editor`, `bunx vitest run src/image.security.test.ts --maxWorkers=2`: check benign HTML attribute export. Run the existing collaboration and mixed-paste undo suites as part of the merge round's full web tests. - Complete real production PDF rendering, clipboard/HTML export and live collaboration checks. Complete the Rust gates that the implementation report left open for calternal-auth and calternal-search. ## Deliverables, gaps and decisions Built: two review documents only, `review-deps.md` and `audit-findings.md`. Known gaps: static evidence only; no clean image build; no runtime or visual evidence; imported feature changes require their own reviews; native notices were not exhaustively verified. No product fix was made. UX gaps closed: none in this read-only job. UX gaps left: runtime PDF and clipboard/export checks listed above; the existing non-selectable PDF text layer remains outside this dependency fix. Product decisions outside DESIGN: none. Review scope follows #810–#813 and the LIGHT job rule. Use existing #812 and #813 as fix owners. Review head SHA: `881b02465050976277990e516b5671731cdcfbb7`. Atomic review commits: `20ddab598`, `310ed222d`, `881b02465`. Gate output: no build or test gates ran under the LIGHT rule. `git diff --check` exited 0 with no output; the working tree is clean.
Author
Owner

Starting the independent-review fixes for #810 on branch job/deps, based at 440e19dce23040ac8ebaae88f0469b6535b1afcb. I read the binding repo docs, #810, and review findings from #812 and #813. I will merge origin/dev, then fix the one P1 and both P2 findings with regression tests that fail against the reviewed code.

Starting the independent-review fixes for #810 on branch `job/deps`, based at `440e19dce23040ac8ebaae88f0469b6535b1afcb`. I read the binding repo docs, #810, and review findings from #812 and #813. I will merge `origin/dev`, then fix the one P1 and both P2 findings with regression tests that fail against the reviewed code.
Author
Owner

Completed: independent review fixes for #810

Branch: job/deps
Base: 440e19dce23040ac8ebaae88f0469b6535b1afcb
Head: 826f820f0c28e8f49deb956ced3176c69756ec1f

Built

  • Fixed the #813 CA bootstrap order in all production APT stages. Each stage installs ca-certificates from the dated Debian snapshot over HTTP while APT signature checks remain enabled, then switches to the same snapshot over HTTPS.
  • Fixed the #812 Cargo licence refresh path. It checks the sparse-index checksum against the lock, verifies cached archive bytes (or verifies a download), and reads the exact Cargo.toml from the archive. Extracted source trees no longer decide the licence.
  • Added model licence evidence to the ongoing #812 check. It covers model IDs, the CLIP upstream ID, immutable revisions, every declared asset SHA-256, approved licences, reviewed reasons and HTTPS source URLs. New model entries, changed revisions or hashes, missing evidence and unapproved licences fail the same policy pass.

Files

Containerfile; deploy/Containerfile.runtime; deploy/nested-podman/Containerfile; scripts/supply_chain_policy.py; scripts/test_supply_chain_policy.py; scripts/dependency-policy.json; scripts/dependency_policy.py; scripts/refresh_dependency_license_inventory.py; scripts/test_dependency_policy.py.

Commits

  • 656aafd6a — bootstrap trusted CAs before HTTPS APT.
  • ea6a37844 — bind dependency licence checks to reviewed sources.
  • 826f820f0 — document the signed CA bootstrap invariant.

Gate output

....................
----------------------------------------------------------------------
Ran 20 tests in 0.498s

OK
.......
----------------------------------------------------------------------
Ran 7 tests in 0.003s

OK
PASS workflow action SHAs, container image digests and dated Debian snapshots

python3 -m json.tool scripts/dependency-policy.json and git diff --check exited 0 with no output. Rust gates were not applicable because no Rust crate changed. Web gates were not applicable because no web code changed. cargo clean output: Removed 1 file, 356B total. apps/web/build was absent.

Known gaps

  • Clean container image builds and python3 scripts/dependency_policy.py --check were not run in this job; the verification policy reserves them for the merge round. Release readiness still requires the clean build confirmation requested by #813.
  • No API, UI or user-facing feature changed. UX gaps closed/left: not applicable.

Decisions

The model evidence schema is an implementation choice outside DESIGN: static policy records bind each manifest path to its model identity, revision, licence source and asset hashes. The two reviewed sources are the pinned MiniLM revision and the OpenAI CLIP licence, with the pinned Xenova ONNX mirror revision. No product decision outside DESIGN was needed.

For the merge round

  • python3 -m unittest discover -s scripts -p 'test_dependency_policy.py' and python3 -m unittest discover -s scripts -p 'test_supply_chain_policy.py': rerun the regression suites on the combined branch.
  • python3 scripts/dependency_policy.py --check and python3 scripts/supply_chain_policy.py --check: verify the combined lock inventory, advisory policy, model evidence and immutable build inputs.
  • podman build --no-cache -f Containerfile .: prove a clean root image can fetch and install its pinned APT packages.
  • podman build --no-cache --target codec-build -f deploy/Containerfile.runtime .: prove the clean codec stage bootstraps package metadata and installs its pinned build dependencies.
  • After preparing the same server and agent artifacts as the pre-image-build part of deploy/deploy-cloud.sh, run:
    podman build --no-cache --format docker --platform linux/amd64 -f deploy/Containerfile.runtime \
      --build-arg BINARY=target/deploy/calternal-server-amd64 \
      --build-arg AGENT_IMAGE_ARCHIVE=target/deploy/calternal-agent-amd64.tar \
      -t localhost/calternal-cloud:review .
    
    This proves the complete runtime stage can install its packages with the real inputs.
  • podman build --no-cache --file deploy/nested-podman/Containerfile --tag localhost/calternal-nested-podman:review deploy/nested-podman: prove the standalone nested-Podman image can bootstrap and install its pinned packages.
  • Repeat clean image builds and compare resolved package identities, as #813 requires. Do not run the deploy portion of deploy/deploy-cloud.sh for these checks.
# Completed: independent review fixes for #810 Branch: `job/deps` Base: `440e19dce23040ac8ebaae88f0469b6535b1afcb` Head: `826f820f0c28e8f49deb956ced3176c69756ec1f` ## Built - Fixed the #813 CA bootstrap order in all production APT stages. Each stage installs `ca-certificates` from the dated Debian snapshot over HTTP while APT signature checks remain enabled, then switches to the same snapshot over HTTPS. - Fixed the #812 Cargo licence refresh path. It checks the sparse-index checksum against the lock, verifies cached archive bytes (or verifies a download), and reads the exact Cargo.toml from the archive. Extracted source trees no longer decide the licence. - Added model licence evidence to the ongoing #812 check. It covers model IDs, the CLIP upstream ID, immutable revisions, every declared asset SHA-256, approved licences, reviewed reasons and HTTPS source URLs. New model entries, changed revisions or hashes, missing evidence and unapproved licences fail the same policy pass. ## Files `Containerfile`; `deploy/Containerfile.runtime`; `deploy/nested-podman/Containerfile`; `scripts/supply_chain_policy.py`; `scripts/test_supply_chain_policy.py`; `scripts/dependency-policy.json`; `scripts/dependency_policy.py`; `scripts/refresh_dependency_license_inventory.py`; `scripts/test_dependency_policy.py`. ## Commits - `656aafd6a` — bootstrap trusted CAs before HTTPS APT. - `ea6a37844` — bind dependency licence checks to reviewed sources. - `826f820f0` — document the signed CA bootstrap invariant. ## Gate output ```text .................... ---------------------------------------------------------------------- Ran 20 tests in 0.498s OK ....... ---------------------------------------------------------------------- Ran 7 tests in 0.003s OK PASS workflow action SHAs, container image digests and dated Debian snapshots ``` `python3 -m json.tool scripts/dependency-policy.json` and `git diff --check` exited 0 with no output. Rust gates were not applicable because no Rust crate changed. Web gates were not applicable because no web code changed. `cargo clean` output: `Removed 1 file, 356B total`. `apps/web/build` was absent. ## Known gaps - Clean container image builds and `python3 scripts/dependency_policy.py --check` were not run in this job; the verification policy reserves them for the merge round. Release readiness still requires the clean build confirmation requested by #813. - No API, UI or user-facing feature changed. UX gaps closed/left: not applicable. ## Decisions The model evidence schema is an implementation choice outside DESIGN: static policy records bind each manifest path to its model identity, revision, licence source and asset hashes. The two reviewed sources are the [pinned MiniLM revision](https://huggingface.co/sentence-transformers/all-MiniLM-L6-v2/tree/1110a243fdf4706b3f48f1d95db1a4f5529b4d41) and the [OpenAI CLIP licence](https://github.com/openai/CLIP/blob/main/LICENSE), with the [pinned Xenova ONNX mirror revision](https://huggingface.co/Xenova/clip-vit-base-patch32/tree/d15189d7028b43f1d3e65039190477f6af591c2a). No product decision outside DESIGN was needed. ## For the merge round - `python3 -m unittest discover -s scripts -p 'test_dependency_policy.py'` and `python3 -m unittest discover -s scripts -p 'test_supply_chain_policy.py'`: rerun the regression suites on the combined branch. - `python3 scripts/dependency_policy.py --check` and `python3 scripts/supply_chain_policy.py --check`: verify the combined lock inventory, advisory policy, model evidence and immutable build inputs. - `podman build --no-cache -f Containerfile .`: prove a clean root image can fetch and install its pinned APT packages. - `podman build --no-cache --target codec-build -f deploy/Containerfile.runtime .`: prove the clean codec stage bootstraps package metadata and installs its pinned build dependencies. - After preparing the same server and agent artifacts as the pre-image-build part of `deploy/deploy-cloud.sh`, run: ```sh podman build --no-cache --format docker --platform linux/amd64 -f deploy/Containerfile.runtime \ --build-arg BINARY=target/deploy/calternal-server-amd64 \ --build-arg AGENT_IMAGE_ARCHIVE=target/deploy/calternal-agent-amd64.tar \ -t localhost/calternal-cloud:review . ``` This proves the complete runtime stage can install its packages with the real inputs. - `podman build --no-cache --file deploy/nested-podman/Containerfile --tag localhost/calternal-nested-podman:review deploy/nested-podman`: prove the standalone nested-Podman image can bootstrap and install its pinned packages. - Repeat clean image builds and compare resolved package identities, as #813 requires. Do not run the deploy portion of `deploy/deploy-cloud.sh` for these checks.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#810
No description provided.