Skip to content

fix(deps): update github.com/semaphoreui/semaphore digest to 7f76984 - #4080

Closed
renovate[bot] wants to merge 1 commit into
developfrom
renovate/github.com-semaphoreui-semaphore-digest
Closed

renovate[bot] wants to merge 1 commit into
developfrom
renovate/github.com-semaphoreui-semaphore-digest

Conversation

@renovate

@renovate renovate Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github.com/semaphoreui/semaphore require digest 7283631 → 7f76984

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to c7a309b).

Scope: This Renovate PR only updates the github.com/semaphoreui/semaphore module pin in pro/. The substantive code pulled in by the new digest was analyzed for newly introduced attack surface.

Key changes in the bumped digest:

  • Prometheus /api/metrics endpoint with Basic Auth middleware (metricsAuthMiddleware)
  • Metrics disabled by default; endpoint returns 401 unless metrics.enabled is true and non-empty username/password are configured
  • Credential comparison uses subtle.ConstantTimeCompare
  • Integration API authorization fixes (project/integration ID verification)
  • Backup runner-token exclusion, commit-hash validation, and other hardening commits

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. The metrics endpoint is appropriately gated, and the remaining digest changes are predominantly security fixes rather than new exposure.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to c7a309b fix(deps): update github.com/semaphoreui/semaphore digest to 79e3d89 Jul 22, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from e517ef1 to 12bd1dc Compare July 22, 2026 12:25

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 79e3d89).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (c7a309b): One additional commit (4a16adee) moves cron validation to the existing authenticated /api/project/{project_id}/schedules/validate endpoint. This is a hardening/UI consistency change, not new exposure.

Key changes in the bumped digest:

  • Prometheus /api/metrics gated by metricsAuthMiddleware (disabled by default; requires non-empty credentials; constant-time compare)
  • CSRF middleware on authenticated API routes (cross-origin state-changing requests blocked; bearer-token clients exempt only when Authorization contains bearer, and auth still validates the token before session fallback)
  • External identity linking with takeover protections (unverified OIDC email ignored; local accounts not adoptable)
  • Integration project-ID verification, backup runner-token exclusion, commit-hash validation, and related hardening

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 79e3d89 fix(deps): update github.com/semaphoreui/semaphore digest to b7244aa Jul 23, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from 12bd1dc to d299a41 Compare July 23, 2026 14:43

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to b7244aa).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (79e3d89):

  • b7244aa — adds a Vault/OpenBao "Skip TLS certificate verification (insecure)" checkbox in SecretStorageForm.vue, wiring item.params.tls_skip_verify (same opt-in pattern as DVLS insecure_tls). Defaults to unchecked; requires CanManageProjectResources to create/update secret storages.
  • 3678a3c0 — documentation-only (AGENTS/plans/2_20/schedule-timezone.md).

Assessment: The TLS skip-verify option is an intentional, admin-controlled configuration for self-signed certificates — not an auth bypass or injection vector. No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from d299a41 to 0273e80 Compare July 23, 2026 17:37
@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to b7244aa fix(deps): update github.com/semaphoreui/semaphore digest to 3c953e4 Jul 23, 2026

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 3c953e4).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (b7244aa):

  • 3c953e42 — documentation-only change to .claude/CLAUDE.md (agent guidelines for HA and security priorities). No runtime code, API surface, or configuration behavior changed.

Key changes in the bumped digest (validated):

  • Prometheus /api/metrics gated by metricsAuthMiddleware (disabled by default; requires non-empty credentials; constant-time compare)
  • CSRF middleware on authenticated API routes (cross-origin state-changing requests blocked; bearer-token clients exempt)
  • External identity linking with takeover protections
  • Integration project-ID verification via IntegrationMiddleware, backup runner-token exclusion, commit-hash validation, and related hardening
  • Vault tls_skip_verify is an intentional, admin-controlled opt-in (requires CanManageProjectResources)

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 3c953e4 fix(deps): update github.com/semaphoreui/semaphore digest to 08fe6cc Jul 23, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from 0273e80 to c9a9051 Compare July 23, 2026 23:19

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 08fe6cc).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (3c953e4):

  • 27243541 — dev-only openai npm bump 6.48.0 → 6.49.0 in web/package-lock.json (used by gulp-gpt-translate.js build tooling; not shipped in production runtime).
  • 08fe6cc1 — merge commit only.

Key changes in the bumped digest (validated):

  • Prometheus /api/metrics gated by metricsAuthMiddleware (disabled by default; requires non-empty credentials; constant-time compare)
  • CSRF middleware on authenticated API routes (cross-origin state-changing requests blocked; bearer-token clients exempt)
  • External identity linking with takeover protections
  • Integration project-ID verification via IntegrationMiddleware, backup runner-token exclusion, commit-hash validation, and related hardening
  • Vault tls_skip_verify is an intentional, admin-controlled opt-in (requires CanManageProjectResources)

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 08fe6cc fix(deps): update github.com/semaphoreui/semaphore digest to 081425d Jul 25, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from c9a9051 to 61423de Compare July 25, 2026 06:47

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Checking for prior threads

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 081425d).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (08fe6cc):

  • 081425d2 — feat(survey_vars): store survey secret variables as task-bound, encrypted access_key rows (owner=task) with task_id + expire_at, for HA-safe remote-runner dispatch.

Security analysis of survey-secrets changes:

  • API isolation: KeyMiddleware and AddKey reject AccessKeyTaskSecret keys; the project keys list filters owner='', so task-bound secrets are not enumerable or readable via generic key endpoints.
  • Encryption & expiry: Secrets are keyring-encrypted via SerializeSecret; DeserializeSecret enforces expire_at centrally (ErrAccessKeyExpired).
  • Dispatch boundary: Plaintext is loaded only in runner poll (GetTaskSurveySecrets) for tasks assigned to the authenticated runner, or in TaskRunner.run for local execution — same trust channel as other decrypted access keys.
  • Lifecycle: Secrets are deleted on terminal task status (finishRun) and by an hourly expired-key sweep; backup export explicitly excludes task-bound keys.
  • No task API leakage: Task.Secret is db:"-" and cleared before persistence; API responses do not return survey secrets.

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 081425d fix(deps): update github.com/semaphoreui/semaphore digest to 2582d70 Jul 26, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from 61423de to 2550000 Compare July 26, 2026 11:36

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 2582d70).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (081425d):

  • 2582d705 — merge-conflict resolution bringing in the survey-variable target feature ("" = CLI, "env" = process environment variable).
  • getSurveyEnvVars / getEnvironmentExtraVars ensure env-target vars are delivered exactly once (excluded from --extra-vars / -var / shell CLI args).
  • Template.Validate() rejects unknown targets; CreateTemplate / UpdateTemplate still enforce the app whitelist (the removed duplicate check in AddTemplate is redundant).
  • IntegrationForm.vue and CI workflow changes are cosmetic / branch-pinning only.

Key changes in the bumped digest (validated):

  • Survey secrets stored as task-bound, encrypted access_key rows with expiry and runner-scoped dispatch (prior review).
  • Prometheus /api/metrics gated by metricsAuthMiddleware (disabled by default; constant-time compare).
  • CSRF middleware, integration project-ID verification, backup runner-token exclusion, commit-hash validation, and related hardening.

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 2582d70 fix(deps): update github.com/semaphoreui/semaphore digest to 9bea2a6 Jul 28, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from 2550000 to c3e4ff0 Compare July 28, 2026 09:48

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 9bea2a6).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (2582d70):

  • 36b27066 — EnvironmentService.Delete now skips synchronized secrets and secrets backed by read-only external storage; only non-synchronized, writable vault-backed secrets are removed after environment deletion. Requires existing authenticated project access via projectEnvManagement routes.
  • baa1443a — documentation submodule update only.
  • 9bea2a6d — CI/Docker PRO builds pin semaphorepro-module to main instead of 2-19-stable; validation helpers refactored to common_errors.NewValidationError (behavior unchanged).

Key changes in the bumped digest (validated):

  • Survey secrets stored as task-bound, encrypted access_key rows with expiry and runner-scoped dispatch.
  • Prometheus /api/metrics gated by metricsAuthMiddleware (disabled by default; constant-time compare).
  • CSRF middleware, integration project-ID verification, backup runner-token exclusion, commit-hash validation, and related hardening.

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. The environment-delete change is a hardening fix for external secret stores, not a new exposure.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 9bea2a6 fix(deps): update github.com/semaphoreui/semaphore digest to 57e1d63 Jul 28, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from c3e4ff0 to 4966d81 Compare July 28, 2026 17:48

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 57e1d63).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (9bea2a6):

  • 68c5869b — unit-test mock updates for task survey-secret encryption interface (test-only).
  • 9f2675fd — UI refactor: extracts HighlightedCard.vue wrapper around integration auth fields (presentation-only; no auth or data-flow change).
  • 57e1d638 — Dredd API-test hooks initialize util.Config.Apps whitelist so fixture templates pass validation (test harness only; no production route change).

Broader digest changes (re-validated):

  • Task survey secrets — stored as encrypted, task-bound AccessKeyTaskSecret keys with expiry; blocked from generic key API (KeyMiddleware returns 404); runner dispatch requires X-Runner-Token auth.
  • Prometheus /api/metrics — gated by metricsAuthMiddleware (requires Metrics.Enabled plus non-empty credentials; constant-time Basic Auth compare).
  • Integration IDOR fixes — IntegrationMiddleware loads integration by (project_id, integration_id); matcher/extract-value handlers verify IntegrationID matches URL context.
  • Commit hash validation — ValidateCommitHash restricts to hex object names before git checkout.
  • Branch-locked templates — CommitHash cleared when AllowOverrideBranchInTask is false.
  • Cron validation — server-side ValidateCronFormat via cron.ParseStandard on schedule create/update.
  • Vault TLS skip-verify — opt-in admin checkbox (tls_skip_verify, default false); not attacker-controllable without project admin access.

New transitive dependencies (Prometheus client, go-jose, etc.) add observability/JWT support already used in-tree; no new externally reachable handlers introduced by the pro/ pin change alone.

No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 57e1d63 fix(deps): update github.com/semaphoreui/semaphore digest to 0bd3589 Jul 29, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from 4966d81 to 2e6bbd0 Compare July 29, 2026 13:59

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 0bd3589).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (57e1d63):

  • 0bd3589 — adds v2.20.1.err.sql undo migration (drops access_key.task_id / expire_at index and columns) and changes TryRollbackMigration to require the .err.sql file (ignoreErrors=false) instead of silently skipping a missing rollback script. Rollback is only invoked from the migration CLI on failed apply or explicit downgrade — not from HTTP routes.
  • AGENTS/plans/2_20/contextual-help-panel.md — documentation only.

Broader digest changes (re-validated):

  • Task survey secrets — stored as encrypted, task-bound AccessKeyTaskSecret keys with expiry; blocked from generic key API (KeyMiddleware returns 404); runner dispatch requires runner-token auth.
  • Prometheus /api/metrics — gated by metricsAuthMiddleware (requires Metrics.Enabled plus non-empty credentials; constant-time Basic Auth compare).
  • Integration IDOR fixes — IntegrationMiddleware loads integration by (project_id, integration_id).
  • Commit hash validation, cron server-side validation, backup runner-token exclusion, CSRF middleware, and related hardening.

New transitive dependencies (Prometheus client, go-jose, etc.) support observability/JWT already used in-tree; the pro/ pin change does not introduce new externally reachable handlers.

No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 0bd3589 fix(deps): update github.com/semaphoreui/semaphore digest to 013abf8 Jul 30, 2026

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 4f1d080, plus services/runners/job_pool.go).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.

Delta since prior review (bb10ba1):

  • 4f1d080 — tryRegisterRunner now aborts registration when TokenFile write fails instead of continuing silently. This hardens runner token persistence; no new attacker-controlled sink.
  • 86d11cb0 — AWS secret storage UI: enables IAM-role checkbox and refactors secret-source toggles. Client-side validation only; backend storage/auth paths unchanged.
  • 4976e916–5c2d6e34 (merged #4159) — shell task output draining via io.Pipe + WaitDelay to prevent hangs from inherited pipes. Reliability fix; no new command execution surface.
  • c0b1ec84–c0748bcc — GetSecretsPath() backward-compatible fallback for legacy secrets_path; admin-configured path only, not user input.
  • 4b25d904 / a7b3c9f1 / workflow UI commits — dependency and cosmetic frontend changes only.

Broader digest range (72836311 → 4f1d080, re-validated):

  • Authn/authz: API-token expiry enforced; metrics endpoint gated by metricsAuthMiddleware; CSRF middleware blocks cross-origin cookie-authenticated state-changing requests (bearer-token clients exempt by design).
  • Secrets: Task-bound survey secrets remain encrypted, expiring, and blocked from generic key APIs; secret-storage APIs require project context.
  • Runner tokens: TokenFile still written with mode 0644 (pre-existing); this PR does not widen that exposure.
  • Supply chain: Pin targets github.com/semaphoreui/semaphore@4f1d080 from the same repository; no third-party source change.

Prior threads: No unresolved automation inline review threads on this PR.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code. No inline finding comments.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate
renovate Bot force-pushed the renovate/github.com-semaphoreui-semaphore-digest branch from ba76eaa to edcb86b Compare August 30, 2026 13:54
@renovate renovate Bot changed the title fix(deps): update github.com/semaphoreui/semaphore digest to 4f1d080 fix(deps): update github.com/semaphoreui/semaphore digest to 000bb72 Aug 30, 2026

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 000bb72).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. The PR diff only touches lockfiles; substantive code pulled in by the new digest was traced for security impact.

Incremental changes since bb10ba1: runner nil-pointer fix in config unmarshaling, shell output draining improvements (WaitDelay/ErrWaitDelay), AWS IAM-role secret-storage UI + StorageRequiresSecret plumbing, and legacy secrets_path fallback via GetSecretsPath().

Reviewed areas (no exploitable issues found):

  • Authn/authz: admin/info remains behind adminMiddleware; CSRF origin/referer checks and API-token expiration enforcement are hardening, not regressions; built-in role permission precedence prevents custom-role slug escalation.
  • Secrets: file-based secret reads still enforce absolute paths and block .. traversal; IAM-role storages skip persisted credentials by design.
  • Injection / execution: shell-output changes address pipe-draining hangs; no new attacker-controlled command injection paths.
  • Supply chain: new transitive deps (Prometheus client, go-jose) are standard observability/crypto libraries with no identified exploitable CVE in this usage.

Prior automation threads: none open; previous assessments superseded.

Verdict: No medium, high, or critical vulnerabilities introduced or exposed by this PR.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 89a2c01).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. The PR diff only touches lockfiles; substantive code is pulled in transitively from the new digest.

Reviewed areas (incremental digest 72836311 → 89a2c01):

  • Config / secrets path (#4133): GetSecretsPath() adds a legacy secrets_path fallback; value is admin-controlled config, not attacker input. File-based secret reads in access_key_serializer_local.go still enforce absolute paths and block .. traversal.
  • Shell output capture (#4159): WaitDelay bounds pipe draining; ErrWaitDelay is treated as a hang-mitigation path. Task runners already execute attacker-supplied commands — this does not introduce a new auth boundary or secret exposure.
  • Runner null-pointer fix: Initializes Runner config before JSON unmarshal; stability fix only.
  • Survey task secrets (#4086): Task-bound keys use AccessKeyTaskSecret owner, are blocked from generic key API routes, encrypted at rest, and excluded from default key listings (owner = '' filter).
  • Prometheus metrics (#4054): /api/metrics is gated by metricsAuthMiddleware (basic auth + enabled flag); Go/process collectors expose standard runtime stats only.
  • Auth hardening in range: API-token expiry check, CSRF middleware for cookie-authenticated state-changing requests.

Supply chain: New transitive deps (Prometheus client, go-jose, protobuf) are standard, widely used libraries pulled from the same upstream module — no suspicious or unreviewed third-party sources.

Prior threads: No unresolved inline review threads; previous automation assessments validated.

Result: No medium, high, or critical vulnerabilities with a plausible attacker-controlled input → sink path were identified in code introduced by this bump.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to a0e71e5).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. The PR diff only touches lockfiles; substantive code pulled in by the new digest was reviewed for authn/authz, injection, secret exposure, SSRF, and supply-chain risk.

Prior threads: No unresolved automation review threads on this PR. Previous assessments (all no-findings) reconciled.

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this bump. Notable security-relevant changes in the digest range are predominantly hardening (CSRF origin checks, metrics basic-auth middleware, API-token expiry enforcement, OIDC account-linking restricted to POST, secrets-path traversal guards, removal of unauthenticated debug/pprof endpoints, task survey-secret keys blocked from generic key APIs).

Transitive deps: New indirect deps (prometheus/*, go-jose/v4, protobuf) support metrics/JWT features; no exploitable sink identified in the pro/ integration surface from this bump alone.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 490e8df).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. The PR diff only touches lockfiles; substantive code is pulled in transitively via the new digest.

Delta since prior review (bb10ba1):

  • c0b1ec84–c0748bcc — GetSecretsPath() legacy secrets_path fallback; file-based secret reads still enforce absolute paths and containment under the configured secrets base (access_key_serializer_local.go).
  • 86d11cb0 — AWS IAM role UI; pro.StorageRequiresSecret() stub still returns true, so create/update paths continue to require credentials — no auth bypass.
  • 5c2d6e34–4976e916 — shell/task output pipe draining refactor; reliability fix, no new attacker-controlled sinks.
  • 90b2f642 — SQLite v2.19.14 migration adds ON DELETE CASCADE for sessions and ON DELETE SET NULL for task authors; improves data hygiene on user deletion.
  • 000bb72d — runner config null-pointer fix during registration; stability only.
  • Frontend lockfile bumps (axios, dayjs, nanoid, core-js) — no new exploitable server-side attack surface in pro/.
  • Docs/submodule and UI-only workflow sidebar changes — no runtime security impact.

Prior threads: No unresolved inline security-review threads on this PR.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 45e2a21).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. The PR diff only touches lockfiles; substantive code is pulled in transitively via the new digest.

Prior threads: No unresolved inline review threads from earlier automation runs. Previous top-level assessments are superseded by this review.

Reviewed areas (transitive changes):

  • Auth/session handling (CSRF middleware, token expiry, OIDC link-mode POST guard, LDAP TLS verification default)
  • Runner registration/auth (hashed one-time tokens, JWT task signing)
  • Metrics endpoint (/api/metrics gated by metrics.enabled + basic auth)
  • Integration webhooks (HMAC/token/basic auth, project-ID verification)
  • Secret storage / access-key handling (survey-secret keys blocked from generic key APIs)
  • Dependency bumps (golang.org/x/crypto 0.53→0.54, golang.org/x/net 0.56→0.57) — upgrades that address known CVEs in older versions

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. No inline finding comments.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 4b39ba1).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest (72836311 → 4b39ba1) was analyzed for newly introduced or exposed attack surface.

Delta since prior review (ff0cf4c):

  • Multi-select survey vars (c7f9d2f0–bb29248c) — backend ValidateSurveyVar hardens template defaults; task values are JSON-encoded via formatVarValue for env/terraform/shell contexts (fixes malformed CLI arg injection).
  • OIDC redirect (eb42b2a3) — oidcSuccessRedirectURL normalizes post-login paths; no open-redirect path (//evil trimmed to /evil).
  • AWS IAM role checkbox (86d11cb0) — UI/admin opt-in for ambient credentials; create/update still requires CanManageProjectResources; pro hook gates access-key creation.
  • Secrets path compat (c0b1ec84) — admin-only GetSecretsPath() fallback; file reads remain constrained under secrets base path with traversal checks.
  • Git hardening (290c135a, 322fe09d) — GitSubmoduleJobs validated ^[1-9][0-9]*$ (admin config); capped clone/pull retries only.
  • Shell output capture (5c2d6e34) — logging reliability fix; ErrWaitDelay does not bypass auth.
  • Frontend deps — axios 1.20.0, cron-parser 5.10.0 (dependency hardening, not new runtime attack surface in pro/).

Prior threads: No unresolved automation review threads on this PR.

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 3bfde9b).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ from 72836311c5b9 to 3bfde9b2ea47. The PR diff only touches lockfiles; substantive code is pulled in transitively.

Reviewed areas:

  • Auth/session: API token expiry enforcement, MFA config migration, TOTP nil-deref guard, CSRF protection middleware (Origin/Referer check with bearer-token exemption that still requires valid token auth downstream).
  • Authz: Environment secret ownership check fix (8fe2f1fb) closes a prior authz bypass; new /api/admin/info and /api/cluster* routes are behind adminMiddleware.
  • New endpoints: /api/metrics gated by basic auth; /.well-known/jwks.json returns 404 when JWT is disabled.
  • Dependencies: go-git security updates, prometheus/go-jose added as indirect deps — no known exploitable CVEs in the pinned versions.

Prior threads: No unresolved automation review threads on this PR.

Outcome: No medium, high, or critical vulnerabilities introduced or exposed by this change. The bump primarily brings in security hardening and bug fixes relative to the previous pin.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to e5ad68d).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.

Delta since prior review (bb10ba1):

  • 5a6ed923 / 3bfde9b2 — Ansible --forks support; template/task args remain JSON-validated before reaching ansible-playbook. SSH agent env forwarding now nil-checks SSHAgent (crash fix, not a boundary change).
  • 290c135a / 4b39ba1b — GitSubmoduleJobs config (^[1-9][0-9]*$, default 4) passed as integer to git --jobs; not attacker-controlled at runtime.
  • c0b1ec84 / d9bebdff — GetSecretsPath() legacy secrets_path fallback; file-based secret reads still enforce absolute paths, reject .., and require paths under the secrets base (access_key_serializer_local.go).
  • 86d11cb0 — AWS IAM-role checkbox (UI only); pro.StorageRequiresSecret still returns true, so no credential-less storage path is reachable.
  • 35573939 / ce1ad605 — task origin links load schedule/integration via authenticated project-scoped APIs; names rendered with Vue text interpolation (auto-escaped).
  • 5c2d6e34 / 8cfb51af — shell output pipe draining refactor; ErrWaitDelay handling affects log capture timing only for already-authorized task execution.
  • 000bb72d — runner config nil-pointer fix on registration.
  • New indirect deps (prometheus/client_golang, go-jose/v4, etc.) — Prometheus /api/metrics remains behind metricsAuthMiddleware (Basic Auth + constant-time compare, disabled when credentials unset).

Prior threads: No unresolved inline security findings from earlier automation runs; all prior assessments validated as still not applicable.

Outcome: No medium, high, or critical vulnerabilities identified in added/modified code paths.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 after synchronize to digest f334b53 (pro/go.mod / pro/go.sum).

Scope: Renovate bumps the github.com/semaphoreui/semaphore module pin in pro/, plus the bundled fix/jwt_for_docker_executor changes (CI PRO-branch resolution, Docker PRO_BRANCH build arg, debug logging in TaskMiddleware).

Delta since prior review:

  • 83d14226 — updates pro/go.mod pin to f334b53; adds transitive deps (Prometheus client stack, go-jose/v4, go-git/v5.19.2, updated golang.org/x/*).
  • f334b53 / #4194 — CI action determine-pro-branch resolves pro_impl branch from GitHub context or tag-containing branches, validated with grep -qx against remote heads before use in quoted git clone -b. Dockerfiles accept PRO_BRANCH build arg (default main) from CI only.
  • api/tasks/tasks.go — adds debug logging on invalid task_id; missing return after 400 is pre-existing and unchanged in control flow.

Dependency digest security (re-validated):

  • Prometheus /api/metrics gated by metricsAuthMiddleware (disabled by default; requires non-empty credentials; constant-time Basic Auth).
  • CSRF middleware on cookie-authenticated state-changing API routes.
  • Survey secrets as task-bound encrypted keys; blocked from generic key API and backups.
  • Integration project-ID verification, commit-hash validation, OIDC identity-linking hardening.
  • go-git/v5.19.2 includes path-traversal and symlink hardening.

Prior threads: No unresolved inline findings from earlier automation runs.

Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.

No inline findings to report.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 4c5daa1).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. The PR diff only touches lockfiles; substantive code pulled in by the new digest was reviewed for injection, auth/authz, secret handling, SSRF/XSS, and supply-chain risk.

Prior threads: No unresolved automation security findings. Previous assessments (through bb10ba1) reported no issues; re-validated the delta 7283631…4c5daa1.

Notable upstream changes reviewed (no exploitable issues found):

  • Prometheus metrics endpoint protected by metricsAuthMiddleware (401 unless enabled with non-empty credentials).
  • CSRF origin/referer checks and API-token expiration enforcement remain sound.
  • Runner check interval and git submodule --jobs values are bounded/validated server-side.
  • JWT/docker-executor PR (#4194) is CI/Docker build wiring plus logging; no auth-boundary change.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod dependency bump to 1774ccb).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.

Delta since prior review (bb10ba1):

  • #4195 (route param refactor): GetStrParam/GetIntParam replaced with *OrAbort helpers that write the error response and return false, requiring callers to return. Fixes prior middleware paths (e.g. TaskMiddleware, appMiddleware) that wrote a 400 but continued with a zero/empty ID — a hardening change, not a new exposure.
  • Runner check interval (#4175): RunnerCheckInterval() clamps to [1, maxRunnerCheckIntervalSec]; heartbeat cadence stays fixed at 1s. UI field is display-only config guidance.
  • Git submodule parallelism: --jobs uses strconv.Itoa(util.Config.GitSubmoduleJobs) with schema rule ^[1-9][0-9]*$ — argv-safe, admin-configured.
  • SSH agent env: getSSHAgentEnv() nil-guards SSHAgent before exporting SSH_AUTH_SOCK — crash fix during install/run.
  • Secret storage IAM role: StorageRequiresSecret skips access-key creation and deletes stale keys on switch to ambient credentials — reduces secret retention.
  • Docker CI: PRO_BRANCH build-arg for pro_impl clone; workflow-controlled, not runtime attacker input.
  • Frontend deps: axios 1.20.0, core-js 3.50.0, nanoid 6.0.1 — routine lockfile updates.

Broader digest range (72836311 → 1774ccb, re-validated):

  • Authn/authz: Metrics (metricsAuthMiddleware), admin routes (/admin/info behind adminMiddleware), and project-resource mutations remain gated; CSRF middleware protects cookie-authenticated state-changing requests.
  • OIDC linking: POST-only for ?link= mode prevents cross-site account-linking CSRF.
  • JWT: ES256 signer with bounded TTL; JWKS public endpoint exposes only the public key.

Prior threads: No unresolved automation inline review threads on this PR.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code. No inline finding comments.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to def5afa).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.

Delta since prior review (bb10ba1):

  • 1774ccb7 / 48cf5cc6 — route param helpers refactored to GetIntParamOrAbort / GetStrParamOrAbort; invalid params still abort with 400/404 before handlers run; no auth bypass.
  • 354970e7 / 692ab36d — runner check interval config with bounded validation (RunnerCheckInterval() clamps to maxRunnerCheckIntervalSec); heartbeat cadence unchanged.
  • 86d11cb0 / services/server/secret_storage_svc.go — optional AWS IAM-role secret storages skip persisted credentials; pro stub still requires secrets; middleware updated accordingly.
  • c0b1ec84 / GetSecretsPath() — legacy secrets_path fallback; local key deserializer still enforces absolute, cleaned base path.
  • 5c2d6e34 / 4976e916 — shell/git output draining via LogCmd finalizer + WaitDelay; prevents hangs, does not bypass auth.
  • 73ce496b / delay-node schema+migration — pro store stubs only in OSS tree; no new unauthenticated API surface.
  • Dependency-only bumps (axios, cron-parser, core-js, nanoid, dayjs) — no exploitable runtime change in server code.

Prior threads: No unresolved inline findings from earlier runs; nothing still applies.

Outcome: No medium, high, or critical vulnerabilities identified in code introduced or exposed by this bump.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod dependency bump to 695c6a1).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. The PR diff only touches pro/go.mod; substantive code pulled in by the new digest was reviewed for security impact.

Areas reviewed:

  • API route-parameter parsing refactor (GetIntParamOrAbort / GetStrParamOrAbort) — callers correctly abort on missing/invalid params; no authz bypass identified.
  • Auth changes (token expiry enforcement, CSRF middleware, metrics basic-auth) — hardening, not regressions.
  • LDAP login — TLS verification now defaults on; filter values escaped with ldap.EscapeFilter.
  • Secret storage / workflow / JWT / encryption additions — gated behind existing project-resource permissions; no unauthenticated exposure found.
  • Runner check-interval config — bounded with overflow guards.
  • Task execution (shell draining, SSH agent env forwarding) — reliability fixes only.

Prior threads: No unresolved inline security findings from earlier automation runs; all prior assessments were "no findings" summaries.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this bump.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@renovate

renovate Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: pro/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 9 additional dependencies were updated

Details:

Package Change
github.com/go-jose/go-jose/v4 v4.1.4 -> v4.1.5
github.com/mattn/go-isatty v0.0.22 -> v0.0.24
github.com/sirupsen/logrus v1.9.4 -> v1.10.2
golang.org/x/crypto v0.54.0 -> v0.57.0
golang.org/x/net v0.57.0 -> v0.58.0
golang.org/x/sys v0.47.0 -> v0.48.0
modernc.org/libc v1.74.1 -> v1.75.6
modernc.org/memory v1.11.0 -> v1.12.1
modernc.org/sqlite v1.54.0 -> v1.58.0

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 62c0ef4).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.

Delta since prior review (bb10ba1):

  • c7f61965 — branch-specific git checkout isolation (branchDirName, withEffectiveBranch). Path separators are stripped/replaced, directories are joined with path.Join, and task-level branch overrides remain gated by AllowOverrideBranchInTask plus git.ValidateGitBranch. This closes a cross-task source-tree race; no new attack surface identified.
  • 3baa6e6f / 7f08f302 — Ansible working_directory with lexical validation (ValidateWorkingDirectoryLexically) and runtime filepath.IsLocal containment in resolveWorkingDirectory. Path traversal blocked.
  • 82b802f2 / 59fc2f05 — go-jose v4.1.5 and go-oidc v3.21.0 dependency bumps. Semaphore uses go-jose only for JWS signing (not JWE decryption), so CVE-2026-34986 is not an applicable attack path here. go-oidc is already past CVE-2025-27144 (fixed in v3.15.0).

Prior threads: No unresolved inline security findings from earlier automation runs; previous assessments reported no findings and remain valid.

Outcome: No medium, high, or critical vulnerabilities with a plausible exploit path were identified in code introduced or exposed by this PR.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 383473a).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ and transitively bumps github.com/go-jose/go-jose/v4 to v4.1.5. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.

Delta since prior review (ff0cf4c):

  • Ansible working directory — repository-relative path with lexical validation (ValidateWorkingDirectoryLexically) and runtime filepath.IsLocal guard in resolveWorkingDirectory; template create/update requires project-manager permissions.
  • Branch-isolated git checkouts — per-branch checkout directories prevent parallel tasks from racing on a shared working tree (hardening).
  • Multi-select survey vars — formatVarValue JSON-encodes arrays/objects for env/terraform/shell contexts (prevents malformed Go formatting, not new injection surface).
  • OIDC post-login redirect — oidcSuccessRedirectURL fixes relative redirect resolution when web_host is unset (hardening).
  • Route param helpers — GetIntParamOrAbort / GetStrParamOrAbort refactor improves error handling; no auth boundary change.
  • AWS IAM-role secret storage (OSS) — optional credential-less storage type; pro.StorageRequiresSecret still returns true in pro builds, so pro behavior unchanged.
  • Dependencies — go-jose/v4 v4.1.5 and go-oidc/v3 v3.21.0 are patch-level refreshes; Semaphore JWT usage is ES256 JWS only (no JWE decryption path).

Prior threads: No unresolved inline finding threads on this PR.

No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 3b339e5).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ and bumps indirect github.com/go-jose/go-jose/v4 to v4.1.5. The PR diff only touches lockfiles; substantive code pulled in by the new digest was reviewed for exploitable issues.

Changes assessed:

  • Dependency updates: go-jose v4.1.5 is a patch bump (supply-chain maintenance, not a new risk).
  • Auth hardening: CSRF middleware on authenticated routes, SameSite=Lax session cookies, API-token expiry checks, OIDC account-linking restricted to POST (prevents cross-site GET CSRF), LDAP filter escaping and TLS verification defaults.
  • Ansible working directory: Lexical validation at template save plus filepath.IsLocal runtime checks block repository escape.
  • Secret storage / workflows / environment secrets: New endpoints sit behind existing project permission middleware (CanManageProjectResources / CanRunProjectTasks); environment secret delete/update now rejects keys from other environments.

Prior threads: No unresolved inline security findings from earlier automation runs; none remain applicable.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this bump.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 9cd15a7).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ and bumps github.com/go-jose/go-jose/v4 v4.1.4 → v4.1.5. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.

Delta since prior review (818a49a):

  • Ansible working directory (fa8b26a3–1839c88b): repository-relative working_directory field with lexical validation (ValidateWorkingDirectoryLexically rejects absolute paths, ../ escapes, Windows drive/UNC paths) and runtime filepath.IsLocal guard in resolveWorkingDirectory. Playbook/inventory paths are resolved from repository root before cmd.Dir is set.
  • Parallel task checkout isolation (c7f61965): keys checkouts by effective branch to prevent cross-task repository mutation — race-condition hardening, not new exposure.
  • Dependency bumps: go-jose/v4 v4.1.5 and go-oidc/v3 v3.21.0 are patch-level updates; go-jose v4.1.4 already remediates CVE-2026-34986.
  • Remaining commits are docs, UI polish, test harness refactors, runner check-interval config, workflow delay nodes, and git-clone retry — no new attacker-controlled input → sensitive sink paths identified.

Broader digest changes (re-validated):

  • Prometheus /api/metrics gated by metricsAuthMiddleware (disabled by default; constant-time Basic Auth).
  • CSRF middleware on cookie-authenticated state-changing requests.
  • Task survey secrets stored as encrypted, task-bound keys excluded from generic key API.
  • Integration project-ID verification, commit-hash validation, backup runner-token exclusion.

Prior threads: No unresolved inline automation review threads were present on this PR.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 9783791).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.

Delta since prior review (bb10ba1 → 9783791):

  • 9783791 — feat(api): allow template_name when creating project tasks (POST /api/project/{project_id}/tasks). Adds resolveTaskTemplate, GetTemplateByName (parameterized SQL, ambiguous-name rejection), template-name uniqueness validation, and migration v2.20.4 (deduplicates legacy names, adds unique index on (project_id, name)).
  • 82b802f2 — go-jose/v4 v4.1.4 → v4.1.5 (patch; already above CVE-2026-34986 fix threshold).
  • 59fc2f05 — go-oidc/v3 v3.21.0 (routine OIDC dependency refresh).
  • c7f61965 — isolate git checkouts by effective branch for parallel tasks (hardening; prevents cross-task file corruption).
  • 74343c0b / 8b79ed6b — Ansible working_directory with lexical + runtime filepath.IsLocal validation (blocks path traversal outside repo root).

Security analysis of template_name (primary new surface):

  • Authn/authz: Route remains behind session/API-token auth, ProjectMiddleware, GetTaskPermissionsMiddleware, and CanRunProjectTasks. GetTemplateByName scopes lookups to project_id from the URL context (no cross-project IDOR). Ambiguous legacy names are rejected rather than silently picking a template.
  • Middleware ordering: GetTaskPermissionsMiddleware runs before resolveTaskTemplate, so template_id=0 when only template_name is supplied means template-specific role grants are not OR'd in. This makes the new path more restrictive for guests with per-template run permissions (functional gap), not an authz bypass — users without CanRunProjectTasks still receive 403.
  • Injection / stored XSS: Template name is bound via parameterized queries; error strings are returned as JSON API responses, not rendered HTML.
  • Migration: migration_2_20_4 renames duplicate template names at upgrade time using parameterized updates; permissions are keyed by template_id, so renames do not alter ACL bindings.

Prior threads: No unresolved automation inline review threads on this PR.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. No inline finding comments.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 5b83baf9-916e-451d-8eb2-abc3715e99e4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to f0eed0b).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ and bumps indirect github.com/go-jose/go-jose/v4 v4.1.4 → v4.1.5. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.

Delta since prior review (9783791):

  • Ansible Galaxy customization (#4160): Adds galaxy_role_args / galaxy_collection_args with strict allowlist validation in pkg/galaxy/install_args.go, enforced on template save (Template.ValidateGalaxyArgs) and re-validated at runtime (galaxyExtraArgs) to cover backup-restore paths. Dangerous flags (--token, -r, -p) are blocked; args are passed via exec.Command argv (no shell). Setting args requires CanManageProjectResources (owner/manager) or delegated template-update permission — consistent with existing template-management trust.
  • Environment YAML editor (#4158): Client-side js-yaml parsing with JSON_SCHEMA, plain-object and finite-number guards; backend still receives JSON extra vars. No new server-side YAML deserialization.
  • TLS HTTP redirect port (#4167): Admin-only config via SEMAPHORE_TLS_* env vars; no user-controlled input.
  • Pointer env var support: Deploy-time config parsing only; not attacker-controlled.
  • go-jose v4.1.5: Routine dependency security patch.

Prior threads: No unresolved inline review threads from earlier automation runs.

Outcome: No medium, high, or critical vulnerabilities identified in added/modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 6b740c2).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ and bumps indirect github.com/go-jose/go-jose/v4 from v4.1.4 → v4.1.5. The PR diff only touches lockfiles; substantive code pulled in by the new digest was spot-checked for attacker-controlled input reaching dangerous sinks.

Prior threads: No unresolved automation review threads on this PR. Previous assessments (all no-findings) are superseded by this run.

Dependency / supply-chain notes:

  • go-jose/v4 v4.1.5 is a maintenance release; the codebase uses JWS signing only (pkg/jwt/signer.go) and does not call ParseEncrypted/KeyUnwrap, so CVE-2026-34986 (JWE panic, fixed in v4.1.4) is not an exploitable path here. The bump is neutral-to-positive.
  • New digest code includes several hardening changes (ansible-galaxy install-arg allowlist in pkg/galaxy/install_args.go, CSRF middleware, API-token expiry enforcement, metrics basic-auth with constant-time compare). template_name task creation resolves templates within the authenticated, project-scoped route (api/projects/tasks.go → GetTemplateByName). Cluster admin endpoints remain behind adminMiddleware.

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added/modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 5b3e4f760eb0).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ plus indirect bumps (go-jose v4.1.5, logrus v1.10.2, golang.org/x/crypto v0.57.0, golang.org/x/net v0.58.0, golang.org/x/sys v0.48.0). The PR diff only touches lockfiles; substantive code is pulled in transitively via the digest.

Reviewed upstream changes in the new digest:

  • Ansible Galaxy args (pkg/galaxy/install_args.go): allowlist validation with dangerous flags excluded (--token, path overrides); hardening, not a new attack surface.
  • Task API template_name (api/projects/tasks.go): resolves templates within the authenticated project via parameterized GetTemplateByName; ambiguous names rejected.
  • /api/admin/info: admin-middleware protected; exposes config metadata only to admins.
  • Auth (api/auth.go): API token expiry enforcement, MFA session verification refinements, OIDC link-mode POST-only CSRF mitigation, metrics basic-auth with constant-time compare.

Prior threads: No unresolved automation review threads; previous assessments remain valid (no findings).

Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review — no findings

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to c7cf726).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/ plus transitive indirect dependencies (go-jose, logrus, golang.org/x/crypto, golang.org/x/net, golang.org/x/sys, modernc.org/sqlite). The PR diff only touches lockfiles; substantive code is pulled in via the new digest.

Incremental delta since last review (bb10ba1 → c7cf726):

  • Dependency bumps (oauth2, crypto, sqlite, js-yaml v5, logrus, svgo) — security-maintenance updates, no new attack surface.
  • Ansible Galaxy customization (pkg/galaxy/install_args.go) — allowlist validation blocks dangerous flags (--token, path overrides); tested.
  • Environment YAML editor (EnvironmentForm.vue) — uses js-yaml with JSON_SCHEMA, enforces plain-object roots and finite numeric values; auth-gated project settings only.
  • Minor API helper hardening (GetStrParamOrAbort) — error-handling improvement, not a bypass.

Prior threads: No unresolved inline findings from earlier automation runs; all previously reported concerns remain addressed or were never raised.

Outcome: No medium, high, or critical vulnerabilities identified with a plausible attacker-controlled input path to an exploitable sink.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review — 1 medium finding

Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 7f76984).

Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.

Delta since prior review (bb10ba1): 189 commits including Ansible galaxy arg customization, hide_dry_run/hide_diff, repository-relative working directory, template_name task API, environment YAML editor hardening, and multiple dependency bumps. Working-directory validation, galaxy flag allowlisting (excluding --token/path overrides), and template_name resolution (project-scoped, ambiguity rejected) look sound.

Finding: hide_dry_run / hide_diff do not filter --check / --diff supplied via per-task CLI arguments when allow_override_args_in_task is enabled, despite docs claiming the template "rejects" those flags. See inline comment.

Slack summary: 1 medium finding — hide_dry_run/hide_diff bypass via task arguments when arg override is enabled; no high/critical issues.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

Comment thread pro/go.mod
go 1.26.4

require github.com/semaphoreui/semaphore v0.0.0-20250712180151-72836311c5b9
require github.com/semaphoreui/semaphore v0.0.0-20260910105558-7f76984a7e5d

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium — hide_dry_run / hide_diff bypass via task CLI arguments

The new hide_dry_run / hide_diff template params (digest b76c3ae2) document that they "reject --check / --diff for tasks launched from this template", and getPlaybookArgs correctly gates the dry_run / diff task params (services/tasks/local_executor.go:515-521). However, when allow_override_args_in_task is true, raw task.arguments are appended afterward (:599-600) with no filtering.

Attack path: Operator with CanRunProjectTasks POSTs /api/project/{id}/tasks with arguments: ["--check"] (or ["--diff"]) on a template where the admin enabled both hide_dry_run and allow_override_args_in_task. Ansible runs in check/diff mode despite the intended restriction.

Impact: Policy/control bypass — admins cannot reliably prevent dry-run/diff execution via the new hide flags while arg override remains enabled.

@renovate

renovate Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for the github.com/semaphoreui/semaphore 7f76984 update again.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant