Skip to content

Embed the bootstrap registration template safely - #64974

Merged
pelikhan merged 3 commits into
mainfrom
copilot/sighthound-security-findings
Oct 2, 2026
Merged

pelikhan merged 3 commits into
mainfrom
copilot/sighthound-security-findings

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

The security report flagged command-injection paths in issue-closing handlers and possible template injection in the GitHub App registration page.

  • Registration page: Move the HTML into a statically embedded file. Parse only that embedded template, and pass the registration URL and manifest as execution data.
    //go:embed bootstrap_registration_page.html
    var bootstrapRegistrationPageFS embed.FS
  • Regression coverage: Verify script-like URL and manifest values remain escaped.
  • Issue-closing handlers: The reported exec/asShellArg paths are absent from this checkout; the current handler uses GitHub API calls without shell execution.

Copilot AI linked an issue Oct 2, 2026 that may be closed by this pull request
Copilot AI and others added 2 commits October 2, 2026 08:26
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix security findings in github/gh-aw Embed the bootstrap registration template safely Oct 2, 2026
Copilot AI requested a review from pelikhan October 2, 2026 08:27
@pelikhan
pelikhan marked this pull request as ready for review October 2, 2026 13:18
Copilot AI balanced review requested due to automatic review settings October 2, 2026 13:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The embedded template preserves contextual escaping, regression coverage matches runtime output, and refreshed dependency pins are valid.

Review effort: Balanced
Findings: None

What changed in this PR

Moves the GitHub App registration HTML into a statically embedded template, preventing request-derived values from becoming template source.

Changes:

  • Parses the embedded HTML with html/template.
  • Adds regression coverage for untrusted URL and manifest values.
  • Refreshes generated workflow and action lock data.
File Description
pkg/​cli/​bootstrap_registration_page.html Adds the static registration template.
pkg/​cli/​bootstrap_profile_helpers.go Embeds and parses the template safely.
pkg/​cli/​bootstrap_profile_helpers_test.go Tests contextual escaping.
.github/​workflows/​visual-regression-checker.lock.yml Refreshes generated firewall configuration.
.github/​workflows/​spec-enforcer.lock.yml Updates the coverage action pin.
.github/​workflows/​purelock.lock.yml Updates the coverage action pin.
.github/​aw/​actions-lock.json Synchronizes action pins with workflow sources.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@pelikhan
pelikhan merged commit 7f798e9 into main Oct 2, 2026
34 of 35 checks passed
@pelikhan
pelikhan deleted the copilot/sighthound-security-findings branch October 2, 2026 14:01
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.90.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sighthound] Security findings in github/gh-aw

3 participants