Enforce gh-aw v0.85.3 security compatibility floor#55796
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot can you ban the range of releases flagged by the advisory? |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Addressed in |
|
@copilot v0.85.4 it's the first valid version that doesn't contain such a misreading of the advisory—or is the advisory… |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Corrected in |
|
@copilot update the skill to make sure to run a schema validator on compat.json (there should be a task in main), also maintain a compat.md that lists why these versions are blocked linking to the advisories |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Addressed in |
|
@copilot ensure that there is a unit test that validate that compat.json is valid w.r.t to the compat schema. |
|
@copilot the skill should tell the agent to provide remediation instructions, similarly to the advisory (see updated content in https://github.com/github/gh-aw/security/advisories/GHSA-8h78-hpm7-29gg) Review the skill wording and habits and apply best practices from the security comunity, known CVE way of wording, specifying things. |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Addressed in |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Addressed in |
|
Category: chore | Risk: medium | Score: 44/100 (impact 20/50, urgency 10/30, quality 14/20) | Action: defer | Batch: workflow-runtime
|
Updates the compatibility policy for GHSA-8h78-hpm7-29gg and adds reusable guidance for translating security advisories into targeted compatibility changes.
Changes
Compatibility enforcement
minimumVersionfromv0.65.3tov0.85.3.Advisory workflow
security-advisory-compat-enforcer.