Skip to content

Tracker: AUDIT.md > 6. Validate Settings, Rulesets, and Secrets #1356

Description

@ptr727

Tracker for AUDIT.md > 6. Validate Settings, Rulesets, and Secrets. Filed under #1315's roll-up of the open prose backlog: every finding a bundle issue enumerated against this unit is listed here once, one line each, naming the issue it came from, and the bundle is closed as a duplicate of this tracker so the finding is not lost and the bundle stops being a unit of work. A new pre-existing finding on this unit gathers here per pr-review-conduct's Merge Gate, numbering continuing this list. This tracker closes when the unit is rewritten and each line below is settled or superseded.

  1. "It preserves and reports bypass_actors without asserting them" describes apply-mode behavior. In check the live list is only read and printed, and nothing is preserved. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  2. The check command is given with no prerequisites, where it hard-fails without admin on the target, an authenticated gh, jq, and a Python interpreter for the description resolution. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  3. "run spec/audit.py [repo]" leaves [repo] undefined beside an / placeholder, where audit.py takes the registry name and prints "Not cataloged" for owner/repo. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  4. "read its Secrets section" names a section audit.py does not print. Secrets findings are secrets:-prefixed lines in one flat block, and a clean repo prints no secrets line at all. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  5. "confirming each required name exists" describes only the presence half: audit.py also raises a defect for a forbidden name present and a drift for a stale name claimed by no mechanism. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  6. "where the mechanism needs it (Docker Hub, codegen App), the Dependabot store too" is incomplete against spec/secrets.json, where nuget-oidc and codecov also declare both stores. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  7. "github-actions when .github/workflows/ is present" diverges from audit.py, which implies the ecosystem only where the directory holds a .yml or .yaml entry. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  8. The snippet's package-ecosystem regex accepts a bare or double-quoted value only, so a single-quoted YAML value reports MISSING, a false drift on the check the bullet mechanizes. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  9. The snippet's four "|| exit 1" tails terminate an interactive shell when pasted, and under set -e a repo without .devcontainer or with an empty dependabot.yml exits non-zero while every printed line says present. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  10. "a repo whose dependabot-updates or update-graph runs are all cancelled with zero steps has this problem" is asserted as diagnostic, and three sentences later called the only visible signal rather than a cause. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  11. "ProjectTemplate itself cannot show the symptom (Document Dependabot Self-Hosted-Runners Account Setting #1015)" narrates the hub's own exemption in a file every fleet repo carries, sourcing an absolute claim to a hub issue a carrier cannot resolve. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  12. "Detection stops there ... Remediation is a separate, manual action" is contradicted by the three imperative remediation sentences that follow it in the same bullet. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  13. "(the file exists, so its absence would instead be a file-presence letter)" binds its pronoun to the tree-implied ecosystem, inverting the classification the sentence just made. The intended subject is dependabot.yml. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  14. is used five times in the snippet and defined nowhere in this unit, so the command is unrunnable from the unit alone. (pre-existing, carried-content pass on Declare the Fleet Label Set and Apply It Through configure.sh #1334)
  15. The lead-in "General settings, labels, and rulesets" names three of the six groups its body says the command checks, dropping the Dependabot security features, so no bullet advertises where those two are validated. (introduced by Declare the Fleet Label Set and Apply It Through configure.sh #1334, left open after its granted round)
  16. "the derived settings and the registry description" over-claims: check asserts the description only when the registry declares one, and otherwise notes "Verify manually" while still reporting a match, where the bullet carves out only bypass_actors as reported rather than asserted. (introduced by Declare the Fleet Label Set and Apply It Through configure.sh #1334, left open after its granted round)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    pre-existingReview finding classed pre-existing per local-strict-review Disposing of FindingsproseA defect in rule or procedure text

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions