aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

Security suite failed (main @ db52d5f)

Đang mở
#593 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
bug
Ngôn ngữ chính
TypeScript
Star
146
Fork
46
Merge trung bình
3 ngày 10 giờ
Pull request đã merge (30 ngày)
24

Mô tả

The root `mise run security` suite failed in GitHub Actions. Use the log tail below and reproduce locally with the same command.

| Field | Value |
| --- | --- |
| Workflow run | [Security #15](https://github.com/aws-samples/sample-autonomous-cloud-coding-agents/actions/runs/29251309033) |
| Ref | `refs/heads/main` |
| SHA | [`db52d5fa7f4d3b66b8f25202e690ae54e4270f13`](https://github.com/aws-samples/sample-autonomous-cloud-coding-agents/commit/db52d5fa7f4d3b66b8f25202e690ae54e4270f13) |
| Actor | @krokoko |
| Event | `schedule` |

### Log tail (last 200 lines)

```text
[//:security:secrets] $ gitleaks git . --no-banner --redact
12:50PM INF 811 commits scanned.
12:50PM INF scanned ~26025917 bytes (26.03 MB) in 3.22s
12:50PM INF no leaks found
[//:security:deps] $ osv-scanner scan --lockfile agent/uv.lock --lockfile yarn.lock
Starting filesystem walk for root: /
Scanned /home/runner/work/sample-autonomous-cloud-coding-agents/sample-autonomous-cloud-coding-agents/agent/uv.lock file and found 128 packages
Scanned /home/runner/work/sample-autonomous-cloud-coding-agents/sample-autonomous-cloud-coding-agents/yarn.lock file and found 1156 packages
End status: 0 dirs visited, 2 inodes visited, 2 Extract calls, 35.973331ms elapsed, 35.973511ms wall time

No issues found
[//:security:sast] $ semgrep scan --config auto --config p/python --config p/typescript --config p/owasp-top-ten --config p/security-audit --error --quiet .
[//:security:sast:masking] $ semgrep test .semgrep/
2/2: ✓ All tests passed
No tests for fixes found.
[//:security:sast:masking] $ mkdir -p test-reports
[//:security:sast:masking] $ semgrep scan --config .semgrep/silent-success-masking.yaml --exclude '.semgrep/*' --sarif-output=test-reports/semgrep-silent-success-masking.sarif --error --quiet .


┌─────────────────┐
│ 7 Code Findings │
└─────────────────┘

agent/src/config.py
❯❱ semgrep.py-silent-success-masking
❰❰ Blocking ❱❱
This except block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-raise (`raise`),
raise a typed error that adds context (`raise XError(...) from exc`), or return a result shape that
encodes the failure. Logging alone is not enough — the failure must reach the caller. If this
fallback is intentional degraded-mode behavior, keep it and add on the return line "# nosemgrep: py-
silent-success-masking -- ".

392┆ return ""
⋮┆----------------------------------------
406┆ return None
⋮┆----------------------------------------
428┆ return ""

agent/src/observability.py
❯❱ semgrep.py-silent-success-masking
❰❰ Blocking ❱❱
This except block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-raise (`raise`),
raise a typed error that adds context (`raise XError(...) from exc`), or return a result shape that
encodes the failure. Logging alone is not enough — the failure must reach the caller. If this
fallback is intentional degraded-mode behavior, keep it and add on the return line "# nosemgrep: py-
silent-success-masking -- ".

86┆ return None

cdk/src/handlers/shared/jira-feedback.ts
❯❱ semgrep.ts-silent-success-masking
❰❰ Blocking ❱❱
This catch block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-throw (`throw err;`),
throw a typed error that adds context, or return a result shape that encodes the failure. Logging
alone is not enough — the failure must reach the caller. If this fallback is intentional degraded-
mode behavior, keep it and add on the return line "// nosemgrep: ts-silent-success-masking -- ".

152┆ return null;

cli/src/commands/jira.ts
❯❱ semgrep.ts-silent-success-masking
❰❰ Blocking ❱❱
This catch block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-throw (`throw err;`),
throw a typed error that adds context, or return a result shape that encodes the failure. Logging
alone is not enough — the failure must reach the caller. If this fallback is intentional degraded-
mode behavior, keep it and add on the return line "// nosemgrep: ts-silent-success-masking -- ".

434┆ return null;

cli/src/commands/linear.ts
❯❱ semgrep.ts-silent-success-masking
❰❰ Blocking ❱❱
This catch block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-throw (`throw err;`),
throw a typed error that adds context, or return a result shape that encodes the failure. Logging
alone is not enough — the failure must reach the caller. If this fallback is intentional degraded-
mode behavior, keep it and add on the return line "// nosemgrep: ts-silent-success-masking -- ".

1630┆ return [];

[//:security:sast:masking] ERROR task failed
```

Close this issue after `mise run security` succeeds on `main` (or the branch you merge to).

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu với năm phát hiện trong agent/src/config.py, agent/src/observability.py, cdk/src/handlers/shared/jira-feedback.ts, cli/src/commands/jira.ts và cli/src/commands/linear.ts. Tái hiện chúng bằng `mise run security`, xem xét từng kết quả che giấu một thành công im lặng và đảm bảo việc xử lý lỗi dự kiến được thể hiện rõ ràng để lệnh hoàn tất thành công trên branch đã được merge vào main.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
github-actions, python, typescript
Lĩnh vực
ci-cd, security
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
52/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.