Skip to content
819 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1//! The security service: what g1t finds wrong in a repository, and the
2//! upkeep that fixes it without a person.
3//!
4//! - Secrets. The repos service refuses pushes that add one
5//! (`push_blocked` says which were allowed and records the rest), and
6//! each repository's history is scanned once, in the background.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily7//! A push too large to scan first is let through, and its new commits
8//! are scanned after they land (`history::advance_push_scan`).
9//! - Alerts are open, dismissed (with a reason, a comment and who) or
10//! fixed, and each keeps an activity log. Likely test values are listed
11//! apart and never block a push or count as critical.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API12//! - Dependencies. On every push to a default branch, and daily, the
13//! lockfiles are read and every package checked against OSV. Each
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily14//! vulnerable package with a fix gets a security update: g1t itself
15//! (`User::system`) opens a pull request raising its version, made in a
16//! sandbox (the runner's `bump`), which lands through the branch's
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent17//! required checks. Only when code has to change is g1t put on an
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily18//! issue for it.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API19//!
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar20//! - The security suite (`g1t_contracts::security_suite`): custom secret
21//! patterns (`patterns`), push protection bypasses, their review and
22//! validity checks (`secret_alerts`), code scanning from SARIF uploads
23//! and its pull request check (`code_scanning`), the dependency graph,
24//! its SBOM and dependency review (`supply_chain`), "Fix with g1t"
25//! (`fixes`), and settings with the workspace's overview (`overview`).
26//! On private repositories its paid parts need the workspace's Security
27//! and quality activation (`suite`); it tells people through events.
28//!
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API29//! Other services reach it over `POST /rpc/<method>`; see
30//! `g1t_contracts::security`.
31
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar32mod code_scanning;
33mod config;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API34mod deps;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar35mod fixes;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API36mod history;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar37mod manifests;
38mod overview;
39mod patterns;
40mod planning;
41mod pull_text;
Merge update PRs close themselves: g1t closes its security and version updates once they are no longer needed, and deletes their branches42mod resolved;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar43mod ranges;
44mod registries;
45mod schedule;
46mod secret_alerts;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily47mod security_updates;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API48mod store;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar49mod suite;
50mod suite_store;
51mod supply_chain;
52mod timezones;
53mod update_store;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily54mod updates;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar55mod version_updates;
56mod yaml;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API57
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look58use g1t_contracts::access::{self, Capability};
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API59use g1t_contracts::events::{Event, WorkspaceRenamed};
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily60use g1t_contracts::security::UPDATE_BRANCH_PREFIX;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look61use g1t_contracts::repos::{GetArgs, PathByIdArgs, Repo, RepoPath, RepoStatus, StatusByIdArgs};
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API62use g1t_contracts::security::*;
63use g1t_contracts::time::rfc3339;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily64use g1t_contracts::{FailureCode, Outcome, User};
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API65use g1t_kit::{args, now_ms, reply, rpc_method};
66use serde::Deserialize;
67use worker::{Context, Env, Fetcher, MessageBatch, Request, Response, Result, ScheduleContext, ScheduledEvent, event};
68
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily69use store::{Activity, RepoRow, Store};
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API70
71/// Repositories whose history is continued per sweep, and pages each.
72const HISTORIES_PER_SWEEP: u32 = 5;
73const PAGES_PER_SWEEP: u32 = 4;
74/// Repositories whose dependencies are read again per sweep.
75const DEPENDENCIES_PER_SWEEP: u32 = 10;
76const DAY_MS: u64 = 24 * 60 * 60 * 1000;
77const MAX_REASON_CHARS: usize = 500;
Merge main (membership, two-factor, GitHub repo roles) into tokens78/// What seeing and dismissing a repository's findings takes: the Write
79/// role, as on GitHub, or a security manager of its workspace. Changing its
80/// security settings takes Admin (`ManageSecurity`).
81const SEE_FINDINGS: Capability = Capability::SecurityAlerts;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API82
83pub struct Security {
84 store: Store,
85 identity: Fetcher,
86 repos: Fetcher,
87 work: Fetcher,
88 runner: Fetcher,
89 billing: Fetcher,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar90 actions: Fetcher,
91 /// The events service: security events for webhooks and the inbox,
92 /// and audit entries. Optional so a deployment without the binding
93 /// still scans.
94 events: Option<Fetcher>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API95}
96
97fn fail<T>(code: FailureCode, message: impl Into<String>) -> Outcome<T> {
98 Outcome::fail(code, message)
99}
100
101/// `git.push`, as far as this service reads it.
102#[derive(Deserialize)]
103#[serde(rename_all = "camelCase")]
104struct Pushed {
105 repo_id: String,
106 #[serde(default)]
107 default_branch: bool,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily108 #[serde(default, rename = "ref")]
109 git_ref: String,
110 #[serde(default)]
111 before: Option<String>,
112 #[serde(default)]
113 after: String,
114 /// Too large to scan before it was stored.
115 #[serde(default)]
116 unscanned: bool,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API117}
118
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily119/// `pull.merged`, `pull.closed` and `checks.completed`, as far as this
120/// service reads them.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API121#[derive(Deserialize)]
122#[serde(rename_all = "camelCase")]
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily123struct PullHappened {
124 repo_id: String,
125 number: u32,
126 #[serde(default)]
127 status: Option<String>,
128}
129
130/// The longest comment a dismissal keeps.
131const MAX_COMMENT_CHARS: usize = MAX_REASON_CHARS;
132/// Activity rows the Security page reads, newest first.
133const ACTIVITY_SHOWN: u32 = 500;
134
135#[derive(Deserialize)]
136#[serde(rename_all = "camelCase")]
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API137struct Created {
138 repo_id: String,
Usage, Billing settings and prepaid AI credit; fixes from the UX audit139 /// Absent from events older than the field.
140 #[serde(default)]
141 is_private: Option<bool>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API142}
143
144impl Security {
145 fn new(env: &Env) -> Result<Self> {
146 Ok(Security {
147 store: Store { db: env.d1("DB")? },
148 identity: env.service("IDENTITY")?,
149 repos: env.service("REPOS")?,
150 work: env.service("WORK")?,
151 runner: env.service("RUNNER")?,
152 billing: env.service("BILLING")?,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar153 actions: env.service("ACTIONS")?,
154 events: env.service("EVENTS").ok(),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API155 })
156 }
157
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look158 /// The repository at `path`, recorded here, if `viewer` may see its
159 /// findings (the Write role) and do `capability`. Findings are for those
160 /// who can change the code: to anyone else the page does not exist,
161 /// public repository or not.
162 async fn member_repo(
163 &self,
164 path: &RepoPath,
165 viewer: &Option<User>,
166 capability: Capability,
167 ) -> Result<Outcome<RepoRow>> {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API168 let hidden = || fail(FailureCode::NotFound, "Repository not found.");
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look169 if viewer.is_none() {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API170 return Ok(hidden());
171 }
172 let repo: Outcome<Repo> =
173 g1t_kit::call(&self.repos, "get", &GetArgs { path: path.clone(), viewer: viewer.clone() }).await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look174 let repo = match repo {
175 Outcome::Ok(repo) if repo.fork_of.is_none() => repo,
176 _ => return Ok(hidden()),
177 };
178 if !access::can(viewer.as_ref(), &repo, SEE_FINDINGS) {
179 return Ok(hidden());
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API180 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look181 if !access::can(viewer.as_ref(), &repo, capability) {
182 return Ok(fail(
183 FailureCode::Forbidden,
184 access::needs(capability, &format!("{}/{}", repo.namespace, repo.name)),
185 ));
186 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar187 let row = self.store.register(&repo.id, &repo.namespace, &repo.name).await?;
188 self.store.set_private(&repo.id, repo.is_private).await?;
189 Ok(Outcome::Ok(row))
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API190 }
191
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look192 /// Whether the repository is neither archived nor deleted. When repos
193 /// cannot say, it is taken as active.
194 async fn active(&self, repo_id: &str) -> Result<bool> {
195 let status: Result<RepoStatus> =
196 g1t_kit::call(&self.repos, "status_by_id", &StatusByIdArgs { id: repo_id.to_owned() }).await;
197 Ok(match status {
198 Ok(status) => status.active(),
199 Err(error) => {
200 worker::console_error!("security: status_by_id {repo_id}: {error}");
201 true
202 }
203 })
204 }
205
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API206 /// Records a repository named in an event, by id. Forks are not
207 /// recorded: a pull request's findings belong to its repository.
208 async fn register_by_id(&self, repo_id: &str) -> Result<Option<RepoRow>> {
209 if let Some(row) = self.store.repo(repo_id).await? {
210 return Ok(Some(row));
211 }
212 let path: Option<RepoPath> = g1t_kit::call(&self.repos, "path_by_id", &PathByIdArgs { id: repo_id.to_owned() }).await?;
213 match path {
214 Some(path) => Ok(Some(self.store.register(repo_id, &path.namespace, &path.name).await?)),
215 None => Ok(None),
216 }
217 }
218
219 async fn overview(&self, a: OverviewArgs) -> Result<Outcome<SecurityOverview>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look220 let mut repo = match self.member_repo(&a.repo, &a.viewer, SEE_FINDINGS).await? {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API221 Outcome::Ok(repo) => repo,
222 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
223 };
224 // The first look at a repository reads its dependencies at once;
225 // its history is scanned in the background.
226 if repo.deps_scanned_at.is_none() {
227 self.scan_dependencies(&repo).await?;
228 repo = self.store.repo(&repo.repo_id).await?.unwrap_or(repo);
229 }
230 let (counts, _, _) = self.store.counts(&repo.repo_id).await?;
231 Ok(Outcome::Ok(SecurityOverview {
232 repo_id: repo.repo_id.clone(),
233 counts,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily234 secret_counts: self.store.secret_counts(&repo.repo_id).await?,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API235 secrets: self.store.secrets(&repo.repo_id).await?,
236 vulnerabilities: self.store.vulnerabilities(&repo.repo_id).await?,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily237 activity: self.store.activity(&repo.repo_id, ACTIVITY_SHOWN).await?,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API238 scan: repo.scan_state(),
239 upkeep: repo.upkeep != 0,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar240 version_updates: self.version_updates_view(&repo).await?,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API241 }))
242 }
243
Merge main (membership, two-factor, GitHub repo roles) into tokens244 /// What dismissing or reopening alert `id` takes: Write, for a secret
245 /// as for a vulnerable dependency, as on GitHub; a security manager may
246 /// too.
247 fn capability_for(_id: &str) -> Capability {
248 SEE_FINDINGS
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily249 }
250
251 async fn dismiss(&self, a: DismissArgs) -> Result<Outcome<AlertChange>> {
252 let repo = match self.member_repo(&a.repo, &Some(a.actor.clone()), Self::capability_for(&a.id)).await? {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API253 Outcome::Ok(repo) => repo,
254 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
255 };
256 if !a.actor.verified {
257 return Ok(fail(FailureCode::Forbidden, "Confirm your email address first."));
258 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily259 let comment: String = a.comment.trim().chars().take(MAX_COMMENT_CHARS).collect();
260 let comment = (!comment.is_empty()).then_some(comment);
261 if let Some(finding) = self.store.secret(&repo.repo_id, &a.id).await? {
262 if !a.reason.for_secrets() {
263 return Ok(fail(
264 FailureCode::Invalid,
265 "A secret is dismissed as false_positive, used_in_tests, revoked or wont_fix.",
266 ));
267 }
268 if finding.state != AlertState::Open {
269 return Ok(fail(FailureCode::Conflict, "This alert is not open. Reopen it first to dismiss it again."));
270 }
271 self.store
272 .dismiss_secret(&repo.repo_id, &a.id, a.reason, &a.actor.username, comment.as_deref())
273 .await?;
274 self.store
275 .record(&repo.repo_id, &[Activity {
276 alert_id: &a.id,
277 action: "dismissed",
278 actor: Some(&a.actor.username),
279 reason: Some(a.reason),
280 comment: comment.as_deref(),
281 number: None,
282 }])
283 .await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar284 let secret = self.store.secret(&repo.repo_id, &a.id).await?;
285 if let Some(secret) = &secret {
286 // Revoked is fixed; any other reason, dismissed.
287 let action = if a.reason == DismissReason::Revoked { "fixed" } else { "dismissed" };
288 let event = g1t_contracts::security_suite::SecurityEvent {
289 reason: Some(a.reason.as_str().to_owned()),
290 ..secret_alerts::secret_event(&repo, secret)
291 };
292 self.alert_event(g1t_contracts::security_suite::AlertType::SecretScanning, action, &repo, event, Some(a.actor.id.clone()))
293 .await;
294 }
295 return Ok(Outcome::Ok(AlertChange { secret, vulnerability: None }));
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily296 }
297 let Some(vuln) = self.store.vulnerability(&repo.repo_id, &a.id).await? else {
298 return Ok(fail(FailureCode::NotFound, "No such alert."));
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API299 };
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily300 if a.reason.for_secrets() {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API301 return Ok(fail(
302 FailureCode::Invalid,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily303 "A dependency is dismissed as fix_started, no_bandwidth, tolerable_risk, inaccurate or not_used.",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API304 ));
305 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily306 if vuln.state != AlertState::Open {
307 return Ok(fail(FailureCode::Conflict, "This alert is not open. Reopen it first to dismiss it again."));
308 }
309 self.store
310 .dismiss_vulnerability(&repo.repo_id, &a.id, a.reason, &a.actor.username, comment.as_deref())
311 .await?;
312 self.store
313 .record(&repo.repo_id, &[Activity {
314 alert_id: &a.id,
315 action: "dismissed",
316 actor: Some(&a.actor.username),
317 reason: Some(a.reason),
318 comment: comment.as_deref(),
319 number: None,
320 }])
321 .await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar322 let vulnerability = self.store.vulnerability(&repo.repo_id, &a.id).await?;
323 if let Some(vuln) = &vulnerability {
324 let event = g1t_contracts::security_suite::SecurityEvent { reason: Some(a.reason.as_str().to_owned()), ..deps::vulnerability_event(&repo, vuln) };
325 self.alert_event(g1t_contracts::security_suite::AlertType::Vulnerability, "dismissed", &repo, event, Some(a.actor.id.clone())).await;
326 }
Merge update PRs close themselves: g1t closes its security and version updates once they are no longer needed, and deletes their branches327 // A security update whose alerts are now all fixed or dismissed closes.
328 if let Err(error) = self.resolve_updates(&repo, None).await {
329 worker::console_error!("security: updates of {} not resolved after a dismissal: {error}", repo.repo_id);
330 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar331 Ok(Outcome::Ok(AlertChange { secret: None, vulnerability }))
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily332 }
333
334 async fn reopen(&self, a: ReopenArgs) -> Result<Outcome<AlertChange>> {
335 let repo = match self.member_repo(&a.repo, &Some(a.actor.clone()), Self::capability_for(&a.id)).await? {
336 Outcome::Ok(repo) => repo,
337 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API338 };
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily339 if !a.actor.verified {
340 return Ok(fail(FailureCode::Forbidden, "Confirm your email address first."));
341 }
342 let reopened = Activity { alert_id: &a.id, action: "reopened", actor: Some(&a.actor.username), reason: None, comment: None, number: None };
343 if let Some(finding) = self.store.secret(&repo.repo_id, &a.id).await? {
344 if finding.state == AlertState::Open {
345 return Ok(fail(FailureCode::Conflict, "This alert is already open."));
346 }
347 // A secret that never landed has nothing to reopen to but blocked.
348 let status = if finding.source == "push" && finding.test_value.is_none() { SecretStatus::Blocked } else { SecretStatus::Open };
349 self.store.reopen_secret(&repo.repo_id, &a.id, status).await?;
350 self.store.record(&repo.repo_id, &[reopened]).await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar351 let secret = self.store.secret(&repo.repo_id, &a.id).await?;
352 if let Some(secret) = &secret {
353 self.alert_event(
354 g1t_contracts::security_suite::AlertType::SecretScanning,
355 "reopened",
356 &repo,
357 secret_alerts::secret_event(&repo, secret),
358 Some(a.actor.id.clone()),
359 )
360 .await;
361 }
362 return Ok(Outcome::Ok(AlertChange { secret, vulnerability: None }));
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily363 }
364 let Some(vuln) = self.store.vulnerability(&repo.repo_id, &a.id).await? else {
365 return Ok(fail(FailureCode::NotFound, "No such alert."));
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API366 };
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily367 if vuln.state != AlertState::Dismissed {
368 return Ok(fail(FailureCode::Conflict, "Only a dismissed alert can be reopened; a fixed one reopens when it is found again."));
369 }
370 self.store.reopen_vulnerability(&repo.repo_id, &a.id).await?;
371 self.store.record(&repo.repo_id, &[reopened]).await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar372 let vulnerability = self.store.vulnerability(&repo.repo_id, &a.id).await?;
373 if let Some(vuln) = &vulnerability {
374 self.alert_event(
375 g1t_contracts::security_suite::AlertType::Vulnerability,
376 "reopened",
377 &repo,
378 deps::vulnerability_event(&repo, vuln),
379 Some(a.actor.id.clone()),
380 )
381 .await;
382 }
383 Ok(Outcome::Ok(AlertChange { secret: None, vulnerability }))
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API384 }
385
386 async fn rescan(&self, a: RescanArgs) -> Result<Outcome<ScanState>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look387 let repo = match self.member_repo(&a.repo, &Some(a.actor.clone()), SEE_FINDINGS).await? {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API388 Outcome::Ok(repo) => repo,
389 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
390 };
391 self.store.restart_history(&repo.repo_id).await?;
392 self.scan_dependencies(&repo).await?;
393 if let Some(fresh) = self.store.repo(&repo.repo_id).await? {
394 self.advance_history(&fresh, 1).await?;
395 }
396 let state = self.store.repo(&repo.repo_id).await?.map(|row| row.scan_state()).unwrap_or_default();
397 Ok(Outcome::Ok(state))
398 }
399
400 async fn set_upkeep(&self, a: SetUpkeepArgs) -> Result<Outcome<bool>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look401 // Whether agents keep its dependencies up to date is one of its
402 // settings.
403 let repo = match self.member_repo(&a.repo, &Some(a.actor.clone()), Capability::ManageSettings).await? {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API404 Outcome::Ok(repo) => repo,
405 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
406 };
407 if !a.actor.verified {
408 return Ok(fail(FailureCode::Forbidden, "Confirm your email address first."));
409 }
410 self.store.set_upkeep(&repo.repo_id, a.enabled, &a.actor.username).await?;
411 Ok(Outcome::Ok(a.enabled))
412 }
413
414 async fn workspace(&self, a: WorkspaceArgs) -> Result<Outcome<Vec<RepoSecurity>>> {
415 let workspace = a.workspace.to_lowercase();
416 if !a.viewer.as_ref().is_some_and(|user| user.is_member(&workspace)) {
417 return Ok(fail(FailureCode::NotFound, "Workspace not found."));
418 }
Usage, Billing settings and prepaid AI credit; fixes from the UX audit419 // Only the repositories whose findings the viewer may see. The
420 // Write role is never had through being public, so treating each
421 // as private changes nothing.
422 let repos: Vec<RepoRow> = self
423 .store
424 .in_namespace(&workspace)
425 .await?
426 .into_iter()
427 .filter(|repo| {
428 let target = access::RepoRef { id: &repo.repo_id, namespace: &workspace, private: true };
429 access::can(a.viewer.as_ref(), target, SEE_FINDINGS)
430 })
431 .collect();
432 // Every repository's counts at once, not one after another.
433 let counts = futures_util::future::try_join_all(repos.iter().map(|repo| self.store.counts(&repo.repo_id))).await?;
434 let list = repos
435 .into_iter()
436 .zip(counts)
437 .map(|(repo, (counts, secrets, vulnerabilities))| RepoSecurity {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API438 repo_id: repo.repo_id,
439 name: repo.name,
440 counts,
441 secrets,
442 vulnerabilities,
443 upkeep: repo.upkeep != 0,
444 dependencies_scanned_at: repo.deps_scanned_at,
Usage, Billing settings and prepaid AI credit; fixes from the UX audit445 })
446 .collect();
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API447 Ok(Outcome::Ok(list))
448 }
449
450 /// Push protection's question: which of these secrets were allowed?
451 /// The others are recorded as blocked, so someone can allow them.
452 async fn push_blocked(&self, a: PushBlockedArgs) -> Result<PushVerdict> {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar453 let repo = self.store.register(&a.repo_id, &a.path.namespace, &a.path.name).await?;
454 if let Some(private) = a.private {
455 self.store.set_private(&a.repo_id, private).await?;
456 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API457 let fingerprints: Vec<String> = a.secrets.iter().map(|secret| secret.fingerprint.clone()).collect();
458 let known = self.store.known(&a.repo_id, &fingerprints).await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar459 let mut allowed = let_through(&known, &a.secrets);
460 // Bypassed with a reason: let through, whatever the alert says now.
461 allowed.extend(self.store.bypassed(&a.repo_id, &fingerprints).await?);
462 allowed.sort();
463 allowed.dedup();
464 let all = a.secrets.clone();
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API465 let fresh: Vec<NewSecret> = a
466 .secrets
467 .into_iter()
468 .filter(|secret| !known.iter().any(|(fingerprint, _, _)| *fingerprint == secret.fingerprint))
469 .collect();
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily470 // A likely test value goes through, so it lands: open, not blocked.
471 let (tests, real): (Vec<NewSecret>, Vec<NewSecret>) = fresh.into_iter().partition(|secret| secret.test_value.is_some());
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API472 self.store
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily473 .add_secrets(&a.repo_id, &real, SecretStatus::Blocked, "push", a.pusher.as_deref())
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API474 .await?;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily475 self.store
476 .add_secrets(&a.repo_id, &tests, SecretStatus::Open, "push", a.pusher.as_deref())
477 .await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar478 let fresh: Vec<String> = real.iter().map(|secret| secret.fingerprint.clone()).collect();
479 self.secrets_found(&repo, &all, "push", &fresh, a.pusher.as_deref()).await?;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API480 let ids = self
481 .store
482 .known(&a.repo_id, &fingerprints)
483 .await?
484 .into_iter()
485 .filter(|(fingerprint, _, _)| !allowed.contains(fingerprint))
486 .map(|(fingerprint, id, _)| (fingerprint, id))
487 .collect();
488 Ok(PushVerdict { allowed, ids })
489 }
490
491 /// What happens on the bus that concerns this service.
492 async fn on_event(&self, event: &Event) -> Result<()> {
493 match event.kind.as_str() {
494 "git.push" => {
495 let Ok(pushed) = serde_json::from_value::<Pushed>(event.data.clone()) else {
496 return Ok(());
497 };
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily498 // Too large to scan before it was stored: its new commits
499 // are scanned now, on whichever branch.
500 if pushed.unscanned
501 && !pushed.after.is_empty()
502 && let Some(repo) = self.register_by_id(&pushed.repo_id).await?
503 {
504 let id = self
505 .store
506 .add_push_scan(&repo.repo_id, &pushed.git_ref, &pushed.after, pushed.before.as_deref(), event.actor.as_deref())
507 .await?;
508 self.advance_push_scan(&id, history::PUSH_PAGES_AT_ONCE).await?;
509 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar510 // A version update's branch, or a grouped security update's,
511 // pushed by its sandbox: time for its pull request.
512 if !pushed.default_branch
513 && let Some(branch) = pushed.git_ref.strip_prefix("refs/heads/")
514 && self.update_pull_pushed(&pushed.repo_id, branch, &pushed.after).await?
515 {
516 return Ok(());
517 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily518 // A security update's branch, pushed by its sandbox: time for
519 // its pull request.
520 if let Some(branch) = pushed.git_ref.strip_prefix("refs/heads/")
521 && branch.starts_with(UPDATE_BRANCH_PREFIX)
522 {
Merge update PRs close themselves: g1t closes its security and version updates once they are no longer needed, and deletes their branches523 self.update_pushed(&pushed.repo_id, branch, &pushed.after).await?;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily524 return Ok(());
525 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API526 if !pushed.default_branch {
527 return Ok(());
528 }
529 if let Some(repo) = self.register_by_id(&pushed.repo_id).await? {
530 self.scan_dependencies(&repo).await?;
531 if repo.history != "done" {
532 self.advance_history(&repo, 1).await?;
533 }
534 }
535 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily536 "pull.merged" | "pull.closed" | "checks.completed" => {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar537 if let Ok(happened) = serde_json::from_value::<PullHappened>(event.data.clone())
538 && !(event.kind != "checks.completed" && self.update_pull_closed(&event.kind, &happened.repo_id, happened.number).await?)
539 {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily540 self.update_pull_event(
541 &event.kind,
542 &happened.repo_id,
543 happened.number,
544 happened.status.as_deref(),
545 event.actor.as_deref(),
546 )
547 .await?;
548 }
Merge update PRs close themselves: g1t closes its security and version updates once they are no longer needed, and deletes their branches549 // One of g1t's update pull requests closed or merged, by g1t
550 // or by a person: its branch goes.
551 if event.kind != "checks.completed"
552 && let Ok(happened) = serde_json::from_value::<PullHappened>(event.data.clone())
553 {
554 self.pull_finished(&happened.repo_id, happened.number).await?;
555 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily556 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar557 "comment.created" => self.update_comment(event).await?,
558 // A pull request opened or its head moved: a dependency update
559 // file it changes is checked (not on `pull.ready`, which moves
560 // nothing), and dependency review runs.
561 "pull.opened" | "pull.updated" | "pull.ready" => {
562 if event.kind != "pull.ready" {
563 self.check_dependabot_file(event).await?;
564 }
565 if let Ok(happened) = serde_json::from_value::<PullHappened>(event.data.clone()) {
566 self.review_pull(&happened.repo_id, happened.number).await?;
567 }
568 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API569 "repo.created" => {
570 if let Ok(created) = serde_json::from_value::<Created>(event.data.clone()) {
Usage, Billing settings and prepaid AI credit; fixes from the UX audit571 // Recorded with its visibility, so the overview never takes a
572 // public repository for a private one.
573 if self.register_by_id(&created.repo_id).await?.is_some()
574 && let Some(private) = created.is_private
575 {
576 self.store.set_private(&created.repo_id, private).await?;
577 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API578 }
579 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar580 "repo.visibility_changed" => {
581 if let Ok(changed) = serde_json::from_value::<g1t_contracts::events::RepoVisibilityChanged>(event.data.clone())
582 && self.store.repo(&changed.repo_id).await?.is_some()
583 {
584 self.store.set_private(&changed.repo_id, changed.is_private).await?;
585 }
586 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look587 // A repository transferred or renamed: it is recorded under its new path.
588 "repo.transferred" | "repo.renamed" => {
589 if let Some(moved) = g1t_kit::transfer::read(event) {
590 // Where it is now, so moves heard out of order end in
591 // the same place.
592 let now: Option<g1t_contracts::repos::RepoPath> = g1t_kit::call(
593 &self.repos,
594 "path_by_id",
595 &g1t_contracts::repos::PathByIdArgs { id: moved.repo_id.clone() },
596 )
597 .await?;
598 let current = now.map_or_else(
599 || moved.destination().to_owned(),
600 |path| format!("{}/{}", path.namespace, path.name),
601 );
602 if let Some((namespace, name)) = current.split_once('/') {
603 self.store.moved(&moved.repo_id, namespace, name).await?;
604 }
605 }
606 }
607 // A repository purged: everything found in it goes.
608 "repo.purged" => {
609 if let Some(g1t_kit::lifecycle::Lifecycle::Purged(purged)) = g1t_kit::lifecycle::read(event) {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar610 self.store.purge_suite(&purged.repo_id).await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look611 self.store.purge(&purged.repo_id).await?;
612 }
613 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API614 "workspace.renamed" => {
615 if let Ok(renamed) = serde_json::from_value::<WorkspaceRenamed>(event.data.clone()) {
616 self.store.rename_namespace(&renamed.stale_slugs(&renamed.to), &renamed.to).await?;
617 }
618 }
619 _ => {}
620 }
621 Ok(())
622 }
623
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily624 /// The sweep: continues history scans and scans of pushes that landed
625 /// unscanned, catches security updates whose sandbox never pushed, and
626 /// reads dependencies that have not been read for a day.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API627 async fn sweep(&self) -> Result<()> {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily628 for scan in self.store.pending_push_scans(HISTORIES_PER_SWEEP).await? {
629 if let Err(error) = self.advance_push_scan(&scan.id, PAGES_PER_SWEEP).await {
630 worker::console_error!("security: push scan {} not continued: {error}", scan.id);
631 }
632 }
633 if let Err(error) = self.stalled_updates().await {
634 worker::console_error!("security: stalled security updates not handled: {error}");
635 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar636 if let Err(error) = self.sweep_suite().await {
637 worker::console_error!("security: daily snapshots and validity checks: {error}");
638 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look639 // Archived and deleted repositories wait; a few more are looked at
640 // so that they do not hold up the rest.
641 let mut histories = 0;
642 for repo in self.store.unfinished_histories(HISTORIES_PER_SWEEP * 4).await? {
643 if histories == HISTORIES_PER_SWEEP {
644 break;
645 }
646 if !self.active(&repo.repo_id).await? {
647 continue;
648 }
649 histories += 1;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API650 if let Err(error) = self.advance_history(&repo, PAGES_PER_SWEEP).await {
651 worker::console_error!("security: history of {} not scanned: {error}", repo.repo_id);
652 }
653 }
654 let day_ago = rfc3339(now_ms().saturating_sub(DAY_MS));
655 for repo in self.store.stale_dependencies(&day_ago, DEPENDENCIES_PER_SWEEP).await? {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look656 if !self.active(&repo.repo_id).await? {
657 self.store
658 .skip_dependencies(&repo.repo_id, "Dependencies are not checked while the repository is archived or deleted.")
659 .await?;
660 continue;
661 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API662 if let Err(error) = self.scan_dependencies(&repo).await {
663 worker::console_error!("security: dependencies of {} not read: {error}", repo.repo_id);
664 }
665 }
666 Ok(())
667 }
668}
669
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily670/// The fingerprints a push may carry: those someone dismissed (allowed),
671/// and likely test values, which are recorded but never stop a push.
672/// `known` is (fingerprint, id, status) of findings already recorded.
673fn let_through(known: &[(String, String, String)], secrets: &[NewSecret]) -> Vec<String> {
674 let mut allowed: Vec<String> = known
675 .iter()
676 .filter(|(_, _, status)| status == "allowed")
677 .map(|(fingerprint, _, _)| fingerprint.clone())
678 .chain(secrets.iter().filter(|secret| secret.test_value.is_some()).map(|secret| secret.fingerprint.clone()))
679 .collect();
680 allowed.sort();
681 allowed.dedup();
682 allowed
683}
684
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API685#[event(fetch)]
686async fn fetch(mut request: Request, env: Env, _ctx: Context) -> Result<Response> {
687 let Some(method) = rpc_method(&request) else {
688 return Response::error("Not found", 404);
689 };
690 let security = Security::new(&env)?;
691 let body: serde_json::Value = request.json().await?;
692 match method.as_str() {
693 "overview" => reply(&security.overview(args(body)?).await?),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily694 "dismiss" => reply(&security.dismiss(args(body)?).await?),
695 "reopen" => reply(&security.reopen(args(body)?).await?),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API696 "rescan" => reply(&security.rescan(args(body)?).await?),
697 "set_upkeep" => reply(&security.set_upkeep(args(body)?).await?),
698 "workspace" => reply(&security.workspace(args(body)?).await?),
699 "push_blocked" => reply(&security.push_blocked(args(body)?).await?),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar700 "check_updates" => reply(&security.check_updates(args(body)?).await?),
701 // The security suite.
702 "patterns_for" => reply(&security.patterns_for(args(body)?).await?),
703 "custom_patterns" => reply(&security.custom_patterns(args(body)?).await?),
704 "save_custom_pattern" => reply(&security.save_custom_pattern(args(body)?).await?),
705 "delete_custom_pattern" => reply(&security.delete_custom_pattern(args(body)?).await?),
706 "dry_run_pattern" => reply(&security.dry_run_pattern(args(body)?).await?),
707 "secret_alert" => reply(&security.secret_alert(args(body)?).await?),
708 "bypass" => reply(&security.bypass(args(body)?).await?),
709 "bypass_requests" => reply(&security.bypass_requests(args(body)?).await?),
710 "review_bypass" => reply(&security.review_bypass(args(body)?).await?),
711 "check_validity" => reply(&security.check_validity(args(body)?).await?),
712 "upload_sarif" => reply(&security.upload_sarif(args(body)?).await?),
713 "sarif_status" => reply(&security.sarif_status(args(body)?).await?),
714 "code_scanning" => reply(&security.code_scanning(args(body)?).await?),
715 "code_alert" => reply(&security.code_alert(args(body)?).await?),
716 "set_code_alert_state" => reply(&security.set_code_alert_state(args(body)?).await?),
717 "pull_code_scanning" => reply(&security.pull_code_scanning(args(body)?).await?),
718 "fix_alert" => reply(&security.fix_alert(args(body)?).await?),
719 "dependency_graph" => reply(&security.dependency_graph(args(body)?).await?),
720 "sbom" => reply(&security.sbom(args(body)?).await?),
721 "dependency_review" => reply(&security.dependency_review(args(body)?).await?),
722 "security_settings" => reply(&security.security_settings(args(body)?).await?),
723 "set_security_settings" => reply(&security.set_security_settings(args(body)?).await?),
724 "workspace_security_settings" => reply(&security.workspace_security_settings(args(body)?).await?),
725 "set_workspace_security_settings" => reply(&security.set_workspace_security_settings(args(body)?).await?),
726 "security_overview" => reply(&security.security_overview(args(body)?).await?),
727 "workspace_alerts" => reply(&security.workspace_alerts(args(body)?).await?),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API728 _ => Response::error("Unknown method", 404),
729 }
730}
731
732#[event(queue)]
733async fn queue(batch: MessageBatch<Event>, env: Env, _ctx: Context) -> Result<()> {
734 let security = Security::new(&env)?;
735 for message in batch.messages()? {
736 let event = message.body();
737 if let Err(error) = security.on_event(event).await {
738 // Scans are idempotent and the sweep catches up, so one failed
739 // event is logged rather than retried.
740 worker::console_error!("security: {} {} failed: {error}", event.kind, event.id);
741 }
742 }
743 Ok(())
744}
745
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar746/// The cron (wrangler.jsonc) that runs version updates that are due.
747const VERSION_UPDATES_CRON: &str = "*/5 * * * *";
748
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API749#[event(scheduled)]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar750async fn scheduled(event: ScheduledEvent, env: Env, _ctx: ScheduleContext) {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API751 match Security::new(&env) {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar752 // Version updates run every few minutes, so a schedule's time is kept.
753 Ok(security) if event.cron() == VERSION_UPDATES_CRON => {
754 if let Err(error) = security.version_update_sweep().await {
755 worker::console_error!("security: the version update sweep failed: {error}");
756 }
757 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API758 Ok(security) => {
759 if let Err(error) = security.sweep().await {
760 worker::console_error!("security: the sweep failed: {error}");
761 }
762 }
763 Err(error) => worker::console_error!("security: could not start: {error}"),
764 }
765}
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily766
767#[cfg(test)]
768mod tests {
769 use super::*;
770
771 fn secret(fingerprint: &str, test_value: Option<&str>) -> NewSecret {
772 NewSecret {
773 fingerprint: fingerprint.into(),
774 kind: "aws_access_key".into(),
775 path: "a.env".into(),
776 line: 1,
777 commit: "c".into(),
778 preview: "AKIA…".into(),
779 test_value: test_value.map(str::to_owned),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar780 pattern_id: None,
781 pattern_name: None,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily782 }
783 }
784
785 #[test]
786 fn dismissed_secrets_and_test_values_go_through() {
787 let known = vec![
788 ("allowed".to_owned(), "sec_1".to_owned(), "allowed".to_owned()),
789 ("resolved".to_owned(), "sec_2".to_owned(), "resolved".to_owned()),
790 ("blocked".to_owned(), "sec_3".to_owned(), "blocked".to_owned()),
791 ];
792 let secrets = [secret("allowed", None), secret("resolved", None), secret("example", Some("it says it is an example")), secret("real", None)];
793 assert_eq!(let_through(&known, &secrets), ["allowed", "example"]);
794 }
795
796 #[test]
797 fn a_push_says_when_it_landed_unscanned() {
798 let pushed: Pushed = serde_json::from_value(serde_json::json!({
799 "repoId": "rep_1", "ref": "refs/heads/import", "after": "abc", "defaultBranch": false, "unscanned": true
800 }))
801 .unwrap();
802 assert!(pushed.unscanned && pushed.before.is_none() && pushed.git_ref == "refs/heads/import");
803 let ordinary: Pushed = serde_json::from_value(serde_json::json!({ "repoId": "rep_1", "ref": "refs/heads/main", "after": "abc", "defaultBranch": true })).unwrap();
804 assert!(!ordinary.unscanned);
805 }
806
807 #[test]
808 fn owners_are_told_what_landed_and_what_to_do() {
809 let one = history::landed_secrets_intro("acme", "rocket", "import", 1);
810 assert!(one.contains("A push to import in acme/rocket") && one.contains("a secret that looks real") && one.contains("Rotate"));
811 assert!(history::landed_secrets_intro("acme", "rocket", "main", 3).contains("3 secrets that look real"));
812 }
813
814 #[test]
815 fn dismissing_a_secret_takes_admin_and_a_dependency_write() {
Merge main (membership, two-factor, GitHub repo roles) into tokens816 assert_eq!(Security::capability_for("sec_1"), Capability::SecurityAlerts);
817 assert_eq!(Security::capability_for("vul_1"), Capability::SecurityAlerts);
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily818 }
819}

This file's history is long; its oldest lines are credited to the oldest commit read.