fix(deps): update github.com/semaphoreui/semaphore digest to 7f76984 - #4080
renovate[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump toc7a309b).Scope: This Renovate PR only updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The substantive code pulled in by the new digest was analyzed for newly introduced attack surface.Key changes in the bumped digest:
- Prometheus
/api/metricsendpoint with Basic Auth middleware (metricsAuthMiddleware)- Metrics disabled by default; endpoint returns 401 unless
metrics.enabledis true and non-empty username/password are configured- Credential comparison uses
subtle.ConstantTimeCompare- Integration API authorization fixes (project/integration ID verification)
- Backup runner-token exclusion, commit-hash validation, and other hardening commits
Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. The metrics endpoint is appropriately gated, and the remaining digest changes are predominantly security fixes rather than new exposure.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
e517ef1 to
12bd1dc
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to79e3d89).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
c7a309b): One additional commit (4a16adee) moves cron validation to the existing authenticated/api/project/{project_id}/schedules/validateendpoint. This is a hardening/UI consistency change, not new exposure.Key changes in the bumped digest:
- Prometheus
/api/metricsgated bymetricsAuthMiddleware(disabled by default; requires non-empty credentials; constant-time compare)- CSRF middleware on authenticated API routes (cross-origin state-changing requests blocked; bearer-token clients exempt only when
Authorizationcontainsbearer, and auth still validates the token before session fallback)- External identity linking with takeover protections (unverified OIDC email ignored; local accounts not adoptable)
- Integration project-ID verification, backup runner-token exclusion, commit-hash validation, and related hardening
Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
12bd1dc to
d299a41
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump tob7244aa).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
79e3d89):
b7244aa— adds a Vault/OpenBao "Skip TLS certificate verification (insecure)" checkbox inSecretStorageForm.vue, wiringitem.params.tls_skip_verify(same opt-in pattern as DVLSinsecure_tls). Defaults to unchecked; requiresCanManageProjectResourcesto create/update secret storages.3678a3c0— documentation-only (AGENTS/plans/2_20/schedule-timezone.md).Assessment: The TLS skip-verify option is an intentional, admin-controlled configuration for self-signed certificates — not an auth bypass or injection vector. No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
d299a41 to
0273e80
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to3c953e4).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
b7244aa):
3c953e42— documentation-only change to.claude/CLAUDE.md(agent guidelines for HA and security priorities). No runtime code, API surface, or configuration behavior changed.Key changes in the bumped digest (validated):
- Prometheus
/api/metricsgated bymetricsAuthMiddleware(disabled by default; requires non-empty credentials; constant-time compare)- CSRF middleware on authenticated API routes (cross-origin state-changing requests blocked; bearer-token clients exempt)
- External identity linking with takeover protections
- Integration project-ID verification via
IntegrationMiddleware, backup runner-token exclusion, commit-hash validation, and related hardening- Vault
tls_skip_verifyis an intentional, admin-controlled opt-in (requiresCanManageProjectResources)Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
0273e80 to
c9a9051
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to08fe6cc).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
3c953e4):
27243541— dev-onlyopenainpm bump6.48.0→6.49.0inweb/package-lock.json(used bygulp-gpt-translate.jsbuild tooling; not shipped in production runtime).08fe6cc1— merge commit only.Key changes in the bumped digest (validated):
- Prometheus
/api/metricsgated bymetricsAuthMiddleware(disabled by default; requires non-empty credentials; constant-time compare)- CSRF middleware on authenticated API routes (cross-origin state-changing requests blocked; bearer-token clients exempt)
- External identity linking with takeover protections
- Integration project-ID verification via
IntegrationMiddleware, backup runner-token exclusion, commit-hash validation, and related hardening- Vault
tls_skip_verifyis an intentional, admin-controlled opt-in (requiresCanManageProjectResources)Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
c9a9051 to
61423de
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to081425d).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
08fe6cc):
081425d2— feat(survey_vars): store survey secret variables as task-bound, encryptedaccess_keyrows (owner=task) withtask_id+expire_at, for HA-safe remote-runner dispatch.Security analysis of survey-secrets changes:
- API isolation:
KeyMiddlewareandAddKeyrejectAccessKeyTaskSecretkeys; the project keys list filtersowner='', so task-bound secrets are not enumerable or readable via generic key endpoints.- Encryption & expiry: Secrets are keyring-encrypted via
SerializeSecret;DeserializeSecretenforcesexpire_atcentrally (ErrAccessKeyExpired).- Dispatch boundary: Plaintext is loaded only in runner poll (
GetTaskSurveySecrets) for tasks assigned to the authenticated runner, or inTaskRunner.runfor local execution — same trust channel as other decrypted access keys.- Lifecycle: Secrets are deleted on terminal task status (
finishRun) and by an hourly expired-key sweep; backup export explicitly excludes task-bound keys.- No task API leakage:
Task.Secretisdb:"-"and cleared before persistence; API responses do not return survey secrets.Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
61423de to
2550000
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to2582d70).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
081425d):
2582d705— merge-conflict resolution bringing in the survey-variabletargetfeature (""= CLI,"env"= process environment variable).getSurveyEnvVars/getEnvironmentExtraVarsensure env-target vars are delivered exactly once (excluded from--extra-vars/-var/ shell CLI args).Template.Validate()rejects unknown targets;CreateTemplate/UpdateTemplatestill enforce the app whitelist (the removed duplicate check inAddTemplateis redundant).IntegrationForm.vueand CI workflow changes are cosmetic / branch-pinning only.Key changes in the bumped digest (validated):
- Survey secrets stored as task-bound, encrypted
access_keyrows with expiry and runner-scoped dispatch (prior review).- Prometheus
/api/metricsgated bymetricsAuthMiddleware(disabled by default; constant-time compare).- CSRF middleware, integration project-ID verification, backup runner-token exclusion, commit-hash validation, and related hardening.
Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
2550000 to
c3e4ff0
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to9bea2a6).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
2582d70):
36b27066—EnvironmentService.Deletenow skips synchronized secrets and secrets backed by read-only external storage; only non-synchronized, writable vault-backed secrets are removed after environment deletion. Requires existing authenticated project access viaprojectEnvManagementroutes.baa1443a— documentation submodule update only.9bea2a6d— CI/Docker PRO builds pinsemaphorepro-moduletomaininstead of2-19-stable; validation helpers refactored tocommon_errors.NewValidationError(behavior unchanged).Key changes in the bumped digest (validated):
- Survey secrets stored as task-bound, encrypted
access_keyrows with expiry and runner-scoped dispatch.- Prometheus
/api/metricsgated bymetricsAuthMiddleware(disabled by default; constant-time compare).- CSRF middleware, integration project-ID verification, backup runner-token exclusion, commit-hash validation, and related hardening.
Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. The environment-delete change is a hardening fix for external secret stores, not a new exposure.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
c3e4ff0 to
4966d81
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to57e1d63).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
9bea2a6):
68c5869b— unit-test mock updates for task survey-secret encryption interface (test-only).9f2675fd— UI refactor: extractsHighlightedCard.vuewrapper around integration auth fields (presentation-only; no auth or data-flow change).57e1d638— Dredd API-test hooks initializeutil.Config.Appswhitelist so fixture templates pass validation (test harness only; no production route change).Broader digest changes (re-validated):
- Task survey secrets — stored as encrypted, task-bound
AccessKeyTaskSecretkeys with expiry; blocked from generic key API (KeyMiddlewarereturns 404); runner dispatch requiresX-Runner-Tokenauth.- Prometheus
/api/metrics— gated bymetricsAuthMiddleware(requiresMetrics.Enabledplus non-empty credentials; constant-time Basic Auth compare).- Integration IDOR fixes —
IntegrationMiddlewareloads integration by(project_id, integration_id); matcher/extract-value handlers verifyIntegrationIDmatches URL context.- Commit hash validation —
ValidateCommitHashrestricts to hex object names before git checkout.- Branch-locked templates —
CommitHashcleared whenAllowOverrideBranchInTaskis false.- Cron validation — server-side
ValidateCronFormatviacron.ParseStandardon schedule create/update.- Vault TLS skip-verify — opt-in admin checkbox (
tls_skip_verify, default false); not attacker-controllable without project admin access.New transitive dependencies (Prometheus client, go-jose, etc.) add observability/JWT support already used in-tree; no new externally reachable handlers introduced by the
pro/pin change alone.No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.
Sent by Cursor Automation: Find vulnerabilities
4966d81 to
2e6bbd0
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to0bd3589).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
57e1d63):
0bd3589— addsv2.20.1.err.sqlundo migration (dropsaccess_key.task_id/expire_atindex and columns) and changesTryRollbackMigrationto require the.err.sqlfile (ignoreErrors=false) instead of silently skipping a missing rollback script. Rollback is only invoked from the migration CLI on failed apply or explicit downgrade — not from HTTP routes.AGENTS/plans/2_20/contextual-help-panel.md— documentation only.Broader digest changes (re-validated):
- Task survey secrets — stored as encrypted, task-bound
AccessKeyTaskSecretkeys with expiry; blocked from generic key API (KeyMiddlewarereturns 404); runner dispatch requires runner-token auth.- Prometheus
/api/metrics— gated bymetricsAuthMiddleware(requiresMetrics.Enabledplus non-empty credentials; constant-time Basic Auth compare).- Integration IDOR fixes —
IntegrationMiddlewareloads integration by(project_id, integration_id).- Commit hash validation, cron server-side validation, backup runner-token exclusion, CSRF middleware, and related hardening.
New transitive dependencies (Prometheus client, go-jose, etc.) support observability/JWT already used in-tree; the
pro/pin change does not introduce new externally reachable handlers.No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to4f1d080, plusservices/runners/job_pool.go).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.Delta since prior review (
bb10ba1):
4f1d080—tryRegisterRunnernow aborts registration whenTokenFilewrite fails instead of continuing silently. This hardens runner token persistence; no new attacker-controlled sink.86d11cb0— AWS secret storage UI: enables IAM-role checkbox and refactors secret-source toggles. Client-side validation only; backend storage/auth paths unchanged.4976e916–5c2d6e34(merged #4159) — shell task output draining viaio.Pipe+WaitDelayto prevent hangs from inherited pipes. Reliability fix; no new command execution surface.c0b1ec84–c0748bcc—GetSecretsPath()backward-compatible fallback for legacysecrets_path; admin-configured path only, not user input.4b25d904/a7b3c9f1/ workflow UI commits — dependency and cosmetic frontend changes only.Broader digest range (
72836311→4f1d080, re-validated):
- Authn/authz: API-token expiry enforced; metrics endpoint gated by
metricsAuthMiddleware; CSRF middleware blocks cross-origin cookie-authenticated state-changing requests (bearer-token clients exempt by design).- Secrets: Task-bound survey secrets remain encrypted, expiring, and blocked from generic key APIs; secret-storage APIs require project context.
- Runner tokens:
TokenFilestill written with mode0644(pre-existing); this PR does not widen that exposure.- Supply chain: Pin targets
github.com/semaphoreui/semaphore@4f1d080from the same repository; no third-party source change.Prior threads: No unresolved automation inline review threads on this PR.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code. No inline finding comments.
Sent by Cursor Automation: Find vulnerabilities
ba76eaa to
edcb86b
Compare
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to000bb72).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The PR diff only touches lockfiles; substantive code pulled in by the new digest was traced for security impact.Incremental changes since
bb10ba1: runner nil-pointer fix in config unmarshaling, shell output draining improvements (WaitDelay/ErrWaitDelay), AWS IAM-role secret-storage UI +StorageRequiresSecretplumbing, and legacysecrets_pathfallback viaGetSecretsPath().Reviewed areas (no exploitable issues found):
- Authn/authz:
admin/inforemains behindadminMiddleware; CSRF origin/referer checks and API-token expiration enforcement are hardening, not regressions; built-in role permission precedence prevents custom-role slug escalation.- Secrets: file-based secret reads still enforce absolute paths and block
..traversal; IAM-role storages skip persisted credentials by design.- Injection / execution: shell-output changes address pipe-draining hangs; no new attacker-controlled command injection paths.
- Supply chain: new transitive deps (Prometheus client, go-jose) are standard observability/crypto libraries with no identified exploitable CVE in this usage.
Prior automation threads: none open; previous assessments superseded.
Verdict: No medium, high, or critical vulnerabilities introduced or exposed by this PR.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to89a2c01).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The PR diff only touches lockfiles; substantive code is pulled in transitively from the new digest.Reviewed areas (incremental digest
72836311→89a2c01):
- Config / secrets path (#4133):
GetSecretsPath()adds a legacysecrets_pathfallback; value is admin-controlled config, not attacker input. File-based secret reads inaccess_key_serializer_local.gostill enforce absolute paths and block..traversal.- Shell output capture (#4159):
WaitDelaybounds pipe draining;ErrWaitDelayis treated as a hang-mitigation path. Task runners already execute attacker-supplied commands — this does not introduce a new auth boundary or secret exposure.- Runner null-pointer fix: Initializes
Runnerconfig before JSON unmarshal; stability fix only.- Survey task secrets (#4086): Task-bound keys use
AccessKeyTaskSecretowner, are blocked from generic key API routes, encrypted at rest, and excluded from default key listings (owner = ''filter).- Prometheus metrics (#4054):
/api/metricsis gated bymetricsAuthMiddleware(basic auth + enabled flag); Go/process collectors expose standard runtime stats only.- Auth hardening in range: API-token expiry check, CSRF middleware for cookie-authenticated state-changing requests.
Supply chain: New transitive deps (Prometheus client,
go-jose, protobuf) are standard, widely used libraries pulled from the same upstream module — no suspicious or unreviewed third-party sources.Prior threads: No unresolved inline review threads; previous automation assessments validated.
Result: No medium, high, or critical vulnerabilities with a plausible attacker-controlled input → sink path were identified in code introduced by this bump.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump toa0e71e5).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The PR diff only touches lockfiles; substantive code pulled in by the new digest was reviewed for authn/authz, injection, secret exposure, SSRF, and supply-chain risk.Prior threads: No unresolved automation review threads on this PR. Previous assessments (all no-findings) reconciled.
Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this bump. Notable security-relevant changes in the digest range are predominantly hardening (CSRF origin checks, metrics basic-auth middleware, API-token expiry enforcement, OIDC account-linking restricted to POST, secrets-path traversal guards, removal of unauthenticated debug/pprof endpoints, task survey-secret keys blocked from generic key APIs).
Transitive deps: New indirect deps (
prometheus/*,go-jose/v4,protobuf) support metrics/JWT features; no exploitable sink identified in thepro/integration surface from this bump alone.Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to490e8df).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The PR diff only touches lockfiles; substantive code is pulled in transitively via the new digest.Delta since prior review (
bb10ba1):
c0b1ec84–c0748bcc—GetSecretsPath()legacysecrets_pathfallback; file-based secret reads still enforce absolute paths and containment under the configured secrets base (access_key_serializer_local.go).86d11cb0— AWS IAM role UI;pro.StorageRequiresSecret()stub still returnstrue, so create/update paths continue to require credentials — no auth bypass.5c2d6e34–4976e916— shell/task output pipe draining refactor; reliability fix, no new attacker-controlled sinks.90b2f642— SQLitev2.19.14migration addsON DELETE CASCADEfor sessions andON DELETE SET NULLfor task authors; improves data hygiene on user deletion.000bb72d— runner config null-pointer fix during registration; stability only.- Frontend lockfile bumps (
axios,dayjs,nanoid,core-js) — no new exploitable server-side attack surface inpro/.- Docs/submodule and UI-only workflow sidebar changes — no runtime security impact.
Prior threads: No unresolved inline security-review threads on this PR.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to45e2a21).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The PR diff only touches lockfiles; substantive code is pulled in transitively via the new digest.Prior threads: No unresolved inline review threads from earlier automation runs. Previous top-level assessments are superseded by this review.
Reviewed areas (transitive changes):
- Auth/session handling (CSRF middleware, token expiry, OIDC link-mode POST guard, LDAP TLS verification default)
- Runner registration/auth (hashed one-time tokens, JWT task signing)
- Metrics endpoint (
/api/metricsgated bymetrics.enabled+ basic auth)- Integration webhooks (HMAC/token/basic auth, project-ID verification)
- Secret storage / access-key handling (survey-secret keys blocked from generic key APIs)
- Dependency bumps (
golang.org/x/crypto0.53→0.54,golang.org/x/net0.56→0.57) — upgrades that address known CVEs in older versionsOutcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. No inline finding comments.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to4b39ba1).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest (72836311→4b39ba1) was analyzed for newly introduced or exposed attack surface.Delta since prior review (
ff0cf4c):
- Multi-select survey vars (
c7f9d2f0–bb29248c) — backendValidateSurveyVarhardens template defaults; task values are JSON-encoded viaformatVarValuefor env/terraform/shell contexts (fixes malformed CLI arg injection).- OIDC redirect (
eb42b2a3) —oidcSuccessRedirectURLnormalizes post-login paths; no open-redirect path (//eviltrimmed to/evil).- AWS IAM role checkbox (
86d11cb0) — UI/admin opt-in for ambient credentials; create/update still requiresCanManageProjectResources; pro hook gates access-key creation.- Secrets path compat (
c0b1ec84) — admin-onlyGetSecretsPath()fallback; file reads remain constrained under secrets base path with traversal checks.- Git hardening (
290c135a,322fe09d) —GitSubmoduleJobsvalidated^[1-9][0-9]*$(admin config); capped clone/pull retries only.- Shell output capture (
5c2d6e34) — logging reliability fix;ErrWaitDelaydoes not bypass auth.- Frontend deps — axios
1.20.0, cron-parser5.10.0(dependency hardening, not new runtime attack surface inpro/).Prior threads: No unresolved automation review threads on this PR.
Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to3bfde9b).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/from72836311c5b9to3bfde9b2ea47. The PR diff only touches lockfiles; substantive code is pulled in transitively.Reviewed areas:
- Auth/session: API token expiry enforcement, MFA config migration, TOTP nil-deref guard, CSRF protection middleware (Origin/Referer check with bearer-token exemption that still requires valid token auth downstream).
- Authz: Environment secret ownership check fix (
8fe2f1fb) closes a prior authz bypass; new/api/admin/infoand/api/cluster*routes are behindadminMiddleware.- New endpoints:
/api/metricsgated by basic auth;/.well-known/jwks.jsonreturns 404 when JWT is disabled.- Dependencies: go-git security updates, prometheus/go-jose added as indirect deps — no known exploitable CVEs in the pinned versions.
Prior threads: No unresolved automation review threads on this PR.
Outcome: No medium, high, or critical vulnerabilities introduced or exposed by this change. The bump primarily brings in security hardening and bug fixes relative to the previous pin.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump toe5ad68d).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.Delta since prior review (
bb10ba1):
5a6ed923/3bfde9b2— Ansible--forkssupport; template/task args remain JSON-validated before reachingansible-playbook. SSH agent env forwarding now nil-checksSSHAgent(crash fix, not a boundary change).290c135a/4b39ba1b—GitSubmoduleJobsconfig (^[1-9][0-9]*$, default 4) passed as integer togit --jobs; not attacker-controlled at runtime.c0b1ec84/d9bebdff—GetSecretsPath()legacysecrets_pathfallback; file-based secret reads still enforce absolute paths, reject.., and require paths under the secrets base (access_key_serializer_local.go).86d11cb0— AWS IAM-role checkbox (UI only);pro.StorageRequiresSecretstill returnstrue, so no credential-less storage path is reachable.35573939/ce1ad605— task origin links load schedule/integration via authenticated project-scoped APIs; names rendered with Vue text interpolation (auto-escaped).5c2d6e34/8cfb51af— shell output pipe draining refactor;ErrWaitDelayhandling affects log capture timing only for already-authorized task execution.000bb72d— runner config nil-pointer fix on registration.- New indirect deps (
prometheus/client_golang,go-jose/v4, etc.) — Prometheus/api/metricsremains behindmetricsAuthMiddleware(Basic Auth + constant-time compare, disabled when credentials unset).Prior threads: No unresolved inline security findings from earlier automation runs; all prior assessments validated as still not applicable.
Outcome: No medium, high, or critical vulnerabilities identified in added/modified code paths.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 after synchronize to digest
f334b53(pro/go.mod/pro/go.sum).Scope: Renovate bumps the
github.com/semaphoreui/semaphoremodule pin inpro/, plus the bundledfix/jwt_for_docker_executorchanges (CI PRO-branch resolution, DockerPRO_BRANCHbuild arg, debug logging inTaskMiddleware).Delta since prior review:
83d14226— updatespro/go.modpin tof334b53; adds transitive deps (Prometheus client stack,go-jose/v4,go-git/v5.19.2, updatedgolang.org/x/*).f334b53/ #4194 — CI actiondetermine-pro-branchresolvespro_implbranch from GitHub context or tag-containing branches, validated withgrep -qxagainst remote heads before use in quotedgit clone -b. Dockerfiles acceptPRO_BRANCHbuild arg (defaultmain) from CI only.api/tasks/tasks.go— adds debug logging on invalidtask_id; missingreturnafter 400 is pre-existing and unchanged in control flow.Dependency digest security (re-validated):
- Prometheus
/api/metricsgated bymetricsAuthMiddleware(disabled by default; requires non-empty credentials; constant-time Basic Auth).- CSRF middleware on cookie-authenticated state-changing API routes.
- Survey secrets as task-bound encrypted keys; blocked from generic key API and backups.
- Integration project-ID verification, commit-hash validation, OIDC identity-linking hardening.
go-git/v5.19.2includes path-traversal and symlink hardening.Prior threads: No unresolved inline findings from earlier automation runs.
Assessment: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.
No inline findings to report.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to4c5daa1).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The PR diff only touches lockfiles; substantive code pulled in by the new digest was reviewed for injection, auth/authz, secret handling, SSRF/XSS, and supply-chain risk.Prior threads: No unresolved automation security findings. Previous assessments (through
bb10ba1) reported no issues; re-validated the delta7283631…4c5daa1.Notable upstream changes reviewed (no exploitable issues found):
- Prometheus metrics endpoint protected by
metricsAuthMiddleware(401 unless enabled with non-empty credentials).- CSRF origin/referer checks and API-token expiration enforcement remain sound.
- Runner check interval and git submodule
--jobsvalues are bounded/validated server-side.- JWT/docker-executor PR (#4194) is CI/Docker build wiring plus logging; no auth-boundary change.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.moddependency bump to1774ccb).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.Delta since prior review (
bb10ba1):
- #4195 (route param refactor):
GetStrParam/GetIntParamreplaced with*OrAborthelpers that write the error response and returnfalse, requiring callers toreturn. Fixes prior middleware paths (e.g.TaskMiddleware,appMiddleware) that wrote a 400 but continued with a zero/empty ID — a hardening change, not a new exposure.- Runner check interval (#4175):
RunnerCheckInterval()clamps to[1, maxRunnerCheckIntervalSec]; heartbeat cadence stays fixed at 1s. UI field is display-only config guidance.- Git submodule parallelism:
--jobsusesstrconv.Itoa(util.Config.GitSubmoduleJobs)with schema rule^[1-9][0-9]*$— argv-safe, admin-configured.- SSH agent env:
getSSHAgentEnv()nil-guardsSSHAgentbefore exportingSSH_AUTH_SOCK— crash fix during install/run.- Secret storage IAM role:
StorageRequiresSecretskips access-key creation and deletes stale keys on switch to ambient credentials — reduces secret retention.- Docker CI:
PRO_BRANCHbuild-arg for pro_impl clone; workflow-controlled, not runtime attacker input.- Frontend deps: axios 1.20.0, core-js 3.50.0, nanoid 6.0.1 — routine lockfile updates.
Broader digest range (
72836311→1774ccb, re-validated):
- Authn/authz: Metrics (
metricsAuthMiddleware), admin routes (/admin/infobehindadminMiddleware), and project-resource mutations remain gated; CSRF middleware protects cookie-authenticated state-changing requests.- OIDC linking: POST-only for
?link=mode prevents cross-site account-linking CSRF.- JWT: ES256 signer with bounded TTL; JWKS public endpoint exposes only the public key.
Prior threads: No unresolved automation inline review threads on this PR.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code. No inline finding comments.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump todef5afa).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.Delta since prior review (
bb10ba1):
1774ccb7/48cf5cc6— route param helpers refactored toGetIntParamOrAbort/GetStrParamOrAbort; invalid params still abort with 400/404 before handlers run; no auth bypass.354970e7/692ab36d— runner check interval config with bounded validation (RunnerCheckInterval()clamps tomaxRunnerCheckIntervalSec); heartbeat cadence unchanged.86d11cb0/services/server/secret_storage_svc.go— optional AWS IAM-role secret storages skip persisted credentials; pro stub still requires secrets; middleware updated accordingly.c0b1ec84/GetSecretsPath()— legacysecrets_pathfallback; local key deserializer still enforces absolute, cleaned base path.5c2d6e34/4976e916— shell/git output draining viaLogCmdfinalizer +WaitDelay; prevents hangs, does not bypass auth.73ce496b/ delay-node schema+migration — pro store stubs only in OSS tree; no new unauthenticated API surface.- Dependency-only bumps (axios, cron-parser, core-js, nanoid, dayjs) — no exploitable runtime change in server code.
Prior threads: No unresolved inline findings from earlier runs; nothing still applies.
Outcome: No medium, high, or critical vulnerabilities identified in code introduced or exposed by this bump.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.moddependency bump to695c6a1).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. The PR diff only touchespro/go.mod; substantive code pulled in by the new digest was reviewed for security impact.Areas reviewed:
- API route-parameter parsing refactor (
GetIntParamOrAbort/GetStrParamOrAbort) — callers correctly abort on missing/invalid params; no authz bypass identified.- Auth changes (token expiry enforcement, CSRF middleware, metrics basic-auth) — hardening, not regressions.
- LDAP login — TLS verification now defaults on; filter values escaped with
ldap.EscapeFilter.- Secret storage / workflow / JWT / encryption additions — gated behind existing project-resource permissions; no unauthenticated exposure found.
- Runner check-interval config — bounded with overflow guards.
- Task execution (shell draining, SSH agent env forwarding) — reliability fixes only.
Prior threads: No unresolved inline security findings from earlier automation runs; all prior assessments were "no findings" summaries.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this bump.
Sent by Cursor Automation: Find vulnerabilities
ℹ️ Artifact update noticeFile name: pro/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to62c0ef4).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.Delta since prior review (
bb10ba1):
c7f61965— branch-specific git checkout isolation (branchDirName,withEffectiveBranch). Path separators are stripped/replaced, directories are joined withpath.Join, and task-level branch overrides remain gated byAllowOverrideBranchInTaskplusgit.ValidateGitBranch. This closes a cross-task source-tree race; no new attack surface identified.3baa6e6f/7f08f302— Ansibleworking_directorywith lexical validation (ValidateWorkingDirectoryLexically) and runtimefilepath.IsLocalcontainment inresolveWorkingDirectory. Path traversal blocked.82b802f2/59fc2f05—go-josev4.1.5 andgo-oidcv3.21.0 dependency bumps. Semaphore uses go-jose only for JWS signing (not JWE decryption), so CVE-2026-34986 is not an applicable attack path here. go-oidc is already past CVE-2025-27144 (fixed in v3.15.0).Prior threads: No unresolved inline security findings from earlier automation runs; previous assessments reported no findings and remain valid.
Outcome: No medium, high, or critical vulnerabilities with a plausible exploit path were identified in code introduced or exposed by this PR.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to383473a).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/and transitively bumpsgithub.com/go-jose/go-jose/v4to v4.1.5. Substantive code pulled in by the new digest was analyzed for newly introduced or exposed attack surface.Delta since prior review (
ff0cf4c):
- Ansible working directory — repository-relative path with lexical validation (
ValidateWorkingDirectoryLexically) and runtimefilepath.IsLocalguard inresolveWorkingDirectory; template create/update requires project-manager permissions.- Branch-isolated git checkouts — per-branch checkout directories prevent parallel tasks from racing on a shared working tree (hardening).
- Multi-select survey vars —
formatVarValueJSON-encodes arrays/objects for env/terraform/shell contexts (prevents malformed Go formatting, not new injection surface).- OIDC post-login redirect —
oidcSuccessRedirectURLfixes relative redirect resolution whenweb_hostis unset (hardening).- Route param helpers —
GetIntParamOrAbort/GetStrParamOrAbortrefactor improves error handling; no auth boundary change.- AWS IAM-role secret storage (OSS) — optional credential-less storage type;
pro.StorageRequiresSecretstill returnstruein pro builds, so pro behavior unchanged.- Dependencies —
go-jose/v4v4.1.5 andgo-oidc/v3v3.21.0 are patch-level refreshes; Semaphore JWT usage is ES256 JWS only (no JWE decryption path).Prior threads: No unresolved inline finding threads on this PR.
No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to3b339e5).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/and bumps indirectgithub.com/go-jose/go-jose/v4to v4.1.5. The PR diff only touches lockfiles; substantive code pulled in by the new digest was reviewed for exploitable issues.Changes assessed:
- Dependency updates:
go-josev4.1.5 is a patch bump (supply-chain maintenance, not a new risk).- Auth hardening: CSRF middleware on authenticated routes,
SameSite=Laxsession cookies, API-token expiry checks, OIDC account-linking restricted to POST (prevents cross-site GET CSRF), LDAP filter escaping and TLS verification defaults.- Ansible working directory: Lexical validation at template save plus
filepath.IsLocalruntime checks block repository escape.- Secret storage / workflows / environment secrets: New endpoints sit behind existing project permission middleware (
CanManageProjectResources/CanRunProjectTasks); environment secret delete/update now rejects keys from other environments.Prior threads: No unresolved inline security findings from earlier automation runs; none remain applicable.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this bump.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to9cd15a7).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/and bumpsgithub.com/go-jose/go-jose/v4v4.1.4→v4.1.5. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.Delta since prior review (
818a49a):
- Ansible working directory (
fa8b26a3–1839c88b): repository-relativeworking_directoryfield with lexical validation (ValidateWorkingDirectoryLexicallyrejects absolute paths,../escapes, Windows drive/UNC paths) and runtimefilepath.IsLocalguard inresolveWorkingDirectory. Playbook/inventory paths are resolved from repository root beforecmd.Diris set.- Parallel task checkout isolation (
c7f61965): keys checkouts by effective branch to prevent cross-task repository mutation — race-condition hardening, not new exposure.- Dependency bumps:
go-jose/v4v4.1.5andgo-oidc/v3v3.21.0are patch-level updates;go-josev4.1.4already remediates CVE-2026-34986.- Remaining commits are docs, UI polish, test harness refactors, runner check-interval config, workflow delay nodes, and git-clone retry — no new attacker-controlled input → sensitive sink paths identified.
Broader digest changes (re-validated):
- Prometheus
/api/metricsgated bymetricsAuthMiddleware(disabled by default; constant-time Basic Auth).- CSRF middleware on cookie-authenticated state-changing requests.
- Task survey secrets stored as encrypted, task-bound keys excluded from generic key API.
- Integration project-ID verification, commit-hash validation, backup runner-token exclusion.
Prior threads: No unresolved inline automation review threads were present on this PR.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to9783791).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.Delta since prior review (
bb10ba1→9783791):
9783791— feat(api): allowtemplate_namewhen creating project tasks (POST /api/project/{project_id}/tasks). AddsresolveTaskTemplate,GetTemplateByName(parameterized SQL, ambiguous-name rejection), template-name uniqueness validation, and migrationv2.20.4(deduplicates legacy names, adds unique index on(project_id, name)).82b802f2—go-jose/v4v4.1.4→v4.1.5(patch; already above CVE-2026-34986 fix threshold).59fc2f05—go-oidc/v3v3.21.0(routine OIDC dependency refresh).c7f61965— isolate git checkouts by effective branch for parallel tasks (hardening; prevents cross-task file corruption).74343c0b/8b79ed6b— Ansibleworking_directorywith lexical + runtimefilepath.IsLocalvalidation (blocks path traversal outside repo root).Security analysis of
template_name(primary new surface):
- Authn/authz: Route remains behind session/API-token auth,
ProjectMiddleware,GetTaskPermissionsMiddleware, andCanRunProjectTasks.GetTemplateByNamescopes lookups toproject_idfrom the URL context (no cross-project IDOR). Ambiguous legacy names are rejected rather than silently picking a template.- Middleware ordering:
GetTaskPermissionsMiddlewareruns beforeresolveTaskTemplate, sotemplate_id=0when onlytemplate_nameis supplied means template-specific role grants are not OR'd in. This makes the new path more restrictive for guests with per-template run permissions (functional gap), not an authz bypass — users withoutCanRunProjectTasksstill receive 403.- Injection / stored XSS: Template name is bound via parameterized queries; error strings are returned as JSON API responses, not rendered HTML.
- Migration:
migration_2_20_4renames duplicate template names at upgrade time using parameterized updates; permissions are keyed bytemplate_id, so renames do not alter ACL bindings.Prior threads: No unresolved automation inline review threads on this PR.
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in code introduced or exposed by this PR. No inline finding comments.
Sent by Cursor Automation: Find vulnerabilities
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump tof0eed0b).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/and bumps indirectgithub.com/go-jose/go-jose/v4v4.1.4→v4.1.5. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, path traversal, and unsafe deserialization.Delta since prior review (
9783791):
- Ansible Galaxy customization (#4160): Adds
galaxy_role_args/galaxy_collection_argswith strict allowlist validation inpkg/galaxy/install_args.go, enforced on template save (Template.ValidateGalaxyArgs) and re-validated at runtime (galaxyExtraArgs) to cover backup-restore paths. Dangerous flags (--token,-r,-p) are blocked; args are passed viaexec.Commandargv (no shell). Setting args requiresCanManageProjectResources(owner/manager) or delegated template-update permission — consistent with existing template-management trust.- Environment YAML editor (#4158): Client-side
js-yamlparsing withJSON_SCHEMA, plain-object and finite-number guards; backend still receives JSON extra vars. No new server-side YAML deserialization.- TLS HTTP redirect port (#4167): Admin-only config via
SEMAPHORE_TLS_*env vars; no user-controlled input.- Pointer env var support: Deploy-time config parsing only; not attacker-controlled.
go-josev4.1.5: Routine dependency security patch.Prior threads: No unresolved inline review threads from earlier automation runs.
Outcome: No medium, high, or critical vulnerabilities identified in added/modified code.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to6b740c2).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/and bumps indirectgithub.com/go-jose/go-jose/v4from v4.1.4 → v4.1.5. The PR diff only touches lockfiles; substantive code pulled in by the new digest was spot-checked for attacker-controlled input reaching dangerous sinks.Prior threads: No unresolved automation review threads on this PR. Previous assessments (all no-findings) are superseded by this run.
Dependency / supply-chain notes:
go-jose/v4v4.1.5 is a maintenance release; the codebase uses JWS signing only (pkg/jwt/signer.go) and does not callParseEncrypted/KeyUnwrap, so CVE-2026-34986 (JWE panic, fixed in v4.1.4) is not an exploitable path here. The bump is neutral-to-positive.- New digest code includes several hardening changes (ansible-galaxy install-arg allowlist in
pkg/galaxy/install_args.go, CSRF middleware, API-token expiry enforcement, metrics basic-auth with constant-time compare).template_nametask creation resolves templates within the authenticated, project-scoped route (api/projects/tasks.go→GetTemplateByName). Cluster admin endpoints remain behindadminMiddleware.Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added/modified code.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump to5b3e4f760eb0).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/plus indirect bumps (go-josev4.1.5,logrusv1.10.2,golang.org/x/cryptov0.57.0,golang.org/x/netv0.58.0,golang.org/x/sysv0.48.0). The PR diff only touches lockfiles; substantive code is pulled in transitively via the digest.Reviewed upstream changes in the new digest:
- Ansible Galaxy args (
pkg/galaxy/install_args.go): allowlist validation with dangerous flags excluded (--token, path overrides); hardening, not a new attack surface.- Task API
template_name(api/projects/tasks.go): resolves templates within the authenticated project via parameterizedGetTemplateByName; ambiguous names rejected./api/admin/info: admin-middleware protected; exposes config metadata only to admins.- Auth (
api/auth.go): API token expiry enforcement, MFA session verification refinements, OIDC link-mode POST-only CSRF mitigation, metrics basic-auth with constant-time compare.Prior threads: No unresolved automation review threads; previous assessments remain valid (no findings).
Outcome: No medium, high, or critical vulnerabilities with a plausible attack path were identified in added or modified code.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review — no findings
Reviewed PR #4080 (
pro/go.mod/pro/go.sumdependency bump toc7cf726).Scope: Renovate updates the
github.com/semaphoreui/semaphoremodule pin inpro/plus transitive indirect dependencies (go-jose,logrus,golang.org/x/crypto,golang.org/x/net,golang.org/x/sys,modernc.org/sqlite). The PR diff only touches lockfiles; substantive code is pulled in via the new digest.Incremental delta since last review (
bb10ba1→c7cf726):
- Dependency bumps (oauth2, crypto, sqlite, js-yaml v5, logrus, svgo) — security-maintenance updates, no new attack surface.
- Ansible Galaxy customization (
pkg/galaxy/install_args.go) — allowlist validation blocks dangerous flags (--token, path overrides); tested.- Environment YAML editor (
EnvironmentForm.vue) — usesjs-yamlwithJSON_SCHEMA, enforces plain-object roots and finite numeric values; auth-gated project settings only.- Minor API helper hardening (
GetStrParamOrAbort) — error-handling improvement, not a bypass.Prior threads: No unresolved inline findings from earlier automation runs; all previously reported concerns remain addressed or were never raised.
Outcome: No medium, high, or critical vulnerabilities identified with a plausible attacker-controlled input path to an exploitable sink.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Security review — 1 medium finding
Reviewed PR #4080 (pro/go.mod / pro/go.sum dependency bump to 7f76984).
Scope: Renovate updates the github.com/semaphoreui/semaphore module pin in pro/. Substantive code pulled in by the new digest was traced for injection, authn/authz bypass, secret leakage, SSRF/XSS, and unsafe deserialization.
Delta since prior review (bb10ba1): 189 commits including Ansible galaxy arg customization, hide_dry_run/hide_diff, repository-relative working directory, template_name task API, environment YAML editor hardening, and multiple dependency bumps. Working-directory validation, galaxy flag allowlisting (excluding --token/path overrides), and template_name resolution (project-scoped, ambiguity rejected) look sound.
Finding: hide_dry_run / hide_diff do not filter --check / --diff supplied via per-task CLI arguments when allow_override_args_in_task is enabled, despite docs claiming the template "rejects" those flags. See inline comment.
Slack summary: 1 medium finding — hide_dry_run/hide_diff bypass via task arguments when arg override is enabled; no high/critical issues.
Sent by Cursor Automation: Find vulnerabilities
| go 1.26.4 | ||
|
|
||
| require github.com/semaphoreui/semaphore v0.0.0-20250712180151-72836311c5b9 | ||
| require github.com/semaphoreui/semaphore v0.0.0-20260910105558-7f76984a7e5d |
There was a problem hiding this comment.
Medium — hide_dry_run / hide_diff bypass via task CLI arguments
The new hide_dry_run / hide_diff template params (digest b76c3ae2) document that they "reject --check / --diff for tasks launched from this template", and getPlaybookArgs correctly gates the dry_run / diff task params (services/tasks/local_executor.go:515-521). However, when allow_override_args_in_task is true, raw task.arguments are appended afterward (:599-600) with no filtering.
Attack path: Operator with CanRunProjectTasks POSTs /api/project/{id}/tasks with arguments: ["--check"] (or ["--diff"]) on a template where the admin enabled both hide_dry_run and allow_override_args_in_task. Ansible runs in check/diff mode despite the intended restriction.
Impact: Policy/control bypass — admins cannot reliably prevent dry-run/diff execution via the new hide flags while arg override remains enabled.
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update. You will not get PRs for the If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |


This PR contains the following updates:
7283631→7f76984Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.