githubnext / githubnext/gh-aw-cao

[eu-cra-compliance:vulnerability-handling-auditor] github/gh-aw CRA vulnerability handling audit

Closed
#12,164 0 comments 0 reactions 0 assignees View on GitHub
eu-cra-compliance eu-cra-compliance:vulnerability-handling-auditor
Dominant language
JavaScript
Stars
3
Forks
1
Avg merge
49m
Merged PRs (30d)
837

Description

`TARGET_REPO: github/gh-aw @ b1c86bd47e35ad9a575318e54dcdebcdc0a33e40`

Security intake and scanning evidence is present, and public advisories plus release automation show an active vulnerability-handling lifecycle. The main gaps are missing visible evidence for acknowledgement SLAs, supported-version/support-period inventory, end-of-support communication, and a traceable Article 14 escalation path. Several scope and conformity questions need human review.

**Action:** Security/release maintainers SHOULD review the gaps below, confirm support-period and Article 14 escalation controls, and accept this record only if each `GAP_FOUND`, `INCOMPLETE`, and `HUMAN_REVIEW_REQUIRED` row has an owner and evidence source.

## Status Summary

| Topic | Status | Evidence / gap |
| --- | --- | --- |
| Vulnerability disclosure policy and private intake | EVIDENCE_SUFFICIENT | `SECURITY.md` directs reporters to `opensource-security@github.com` and forbids public issue reporting. Verified 2026-09-16. |
| Researcher coordination and confidentiality expectation | EVIDENCE_SUFFICIENT | `SECURITY.md` requests coordinated disclosure and links GitHub Safe Harbor. Verified 2026-09-16. |
| Acknowledgement workflow / SLA | NOT_ASSESSED | No repository-visible acknowledgement timing, ownership, or ticket-state evidence located. |
| Triage ownership and severity assessment | EVIDENCE_SUFFICIENT | Published GHSA records include severity/CVSS/CWE metadata, showing a structured triage path. Verified 2026-09-16. |
| Affected-version identification | EVIDENCE_SUFFICIENT | GHSA records include vulnerable ranges and patched versions where available. Verified 2026-09-16. |
| Root-cause analysis | EVIDENCE_SUFFICIENT | GHSA descriptions include impacted files/components and remediation direction. Verified 2026-09-16. |
| Remediation decision traceability | EVIDENCE_SUFFICIENT | GHSA entries and release workflows together show patching and release promotion controls. Verified 2026-09-16. |
| Regular code/dependency scanning | EVIDENCE_SUFFICIENT | `.github/workflows/codeql.yml`, `security-scan.yml`, `.github/dependabot.yml`, and `license-check.yml` show recurring scanning/monitoring. Verified 2026-09-16. |
| Component inventory / SBOM | EVIDENCE_SUFFICIENT | `SECURITY.md` states SBOM generation on every release in SPDX and CycloneDX. Verified 2026-09-16. |
| Timely security-fix distribution | EVIDENCE_SUFFICIENT | Recent releases exist; `release.md` / `release.lock.yml` automate release, SBOM attachment, and latest promotion controls. Verified 2026-09-16. |
| Free security updates where required | HUMAN_REVIEW_REQUIRED | Public OSS repo evidence suggests updates are published, but CRA role/scope and applicable duty need explicit human legal/product review. |
| Release notes / customer communication | EVIDENCE_SUFFICIENT | Release workflow exists and public GitHub releases are published; exact security-communication practice per incident not fully sampled. |
| Rollback or mitigation path | NOT_ASSESSED | No concise repository-visible rollback/mitigation procedure for security releases was confirmed in sampled evidence. |
| Coordinated upstream/downstream disclosure | EVIDENCE_SUFFICIENT | `SECURITY.md` requests coordinated disclosure; GHSA usage indicates downstream advisory publication capability. |
| CNA / CVE practice where applicable | EVIDENCE_SUFFICIENT | Repository uses GitHub Security Advisories (GHSA). CVE issuance applicability remains context dependent. |
| Handling withheld details | NOT_ASSESSED | No explicit public rule for temporary detail withholding located in sampled evidence. |
| Supported-version inventory | GAP_FOUND | No clear repository-visible supported-version matrix or policy was found. |
| Support period definition | GAP_FOUND | No clear support-period/EOS policy was found in sampled repository files. |
| End-of-support communication | GAP_FOUND | No clear EOS communication procedure was found in sampled repository files. |
| Timestamp preservation across lifecycle | EVIDENCE_SUFFICIENT | GitHub advisories/releases/commits preserve created, updated, published, and release timestamps. Verified 2026-09-16. |
| Article 14 escalation path linkage | GAP_FOUND | No repository-visible pointer to an internal CRA Article 14 assessment/escalation decision path was found. |

## Lifecycle Control Matrix

| Control claim | Status | Source / URL | Verification date |
| --- | --- | --- | --- |
| Private vulnerability intake channel is published | EVIDENCE_SUFFICIENT | `target/SECURITY.md`; https://github.com/github/gh-aw/blob/main/SECURITY.md | 2026-09-16 |
| Public reporting is discouraged for vulnerabilities | EVIDENCE_SUFFICIENT | `target/SECURITY.md`; https://github.com/github/gh-aw/blob/main/SECURITY.md | 2026-09-16 |
| Dependency monitoring is scheduled | EVIDENCE_SUFFICIENT | `target/.github/dependabot.yml`; https://github.com/github/gh-aw/blob/main/.github/dependabot.yml | 2026-09-16 |
| Code scanning is scheduled | EVIDENCE_SUFFICIENT | `target/.github/workflows/codeql.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/codeql.yml | 2026-09-16 |
| Security scanning is scheduled | EVIDENCE_SUFFICIENT | `target/.github/workflows/security-scan.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/security-scan.yml | 2026-09-16 |
| License/composition checking is automated | EVIDENCE_SUFFICIENT | `target/.github/workflows/license-check.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/license-check.yml | 2026-09-16 |
| Security advisories are published with version impact metadata | EVIDENCE_SUFFICIENT | GitHub advisories API for `github/gh-aw`; https://github.com/github/gh-aw/security/advisories | 2026-09-16 |
| Release pipeline contains security-sensitive controls | EVIDENCE_SUFFICIENT | `target/.github/workflows/release.md` and `release.lock.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/release.md | 2026-09-16 |
| Support-period policy is repository-visible | GAP_FOUND | Topic searched in `README.md`, `SECURITY.md`, workflows, and sampled docs; no decisive policy found | 2026-09-16 |
| Article 14 escalation reference is repository-visible | GAP_FOUND | Topic searched in sampled repository materials; no decisive reference found | 2026-09-16 |

## Sampled Traceability

- EVIDENCE_SUFFICIENT: Public GHSA records include `published_at`, `updated_at`, severity, CWE/CVSS, affected package/version range, and patched version fields where available.
- EVIDENCE_SUFFICIENT: Latest observed releases are public prereleases (`v0.89.15`, `v0.89.13`, `v0.89.12`, `v0.89.11`, `v0.89.10`); repository main branch commit date observed as `2026-09-16T11:39:49Z`.
- EVIDENCE_SUFFICIENT: `docs/security-findings-2026-01-19.md` shows documented scan follow-up, but it is a point-in-time artifact rather than a stable support-policy control.

### Prioritized Gaps

1. GAP_FOUND — Publish a concise supported-version and support-period policy for releases/users.
2. GAP_FOUND — Document how end-of-support is communicated and how vulnerability handling continues for supported versions.
3. GAP_FOUND — Add a repository-visible pointer to the internal Article 14 escalation decision path without deciding reportability in public.
4. NOT_ASSESSED — Preserve or expose acknowledgement/coordination timestamps in a durable process record accessible to reviewers.
5. NOT_ASSESSED — Document whether and how security-release rollback/mitigation guidance is communicated when fixes cannot ship immediately.

### What's working

The repository has a nice security baseline: public intake instructions, scheduled CodeQL/gosec/govulncheck/dependency scanning, SBOM generation, and published GHSA records already provide a strong evidence spine for reviewers.

### Regulatory Findings

- Requirement/topic: vulnerabilities and security updates process evidence. Status: EVIDENCE_SUFFICIENT for several operational controls, but not a legal conformity conclusion.
```yaml
source:
instrument: "Regulation (EU) 2024/2847"
provision: "Article 13; Article 14"
authority: "binding"
```
Official URL: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Verification date: 2026-09-16

- Requirement/topic: baseline CRA dates were checked against official sources. Status: EVIDENCE_SUFFICIENT for 10 December 2024, 11 June 2026, 11 September 2026, and 11 December 2027; no discrepancy observed in sampled official sources.
```yaml
source:
instrument: "Regulation (EU) 2024/2847"
provision: "entry into force and application timeline"
authority: "binding"
```
Official URL: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Verification date: 2026-09-16

- Requirement/topic: Commission CRA guidance dated 27 July 2026 exists, but is non-binding. Status: EVIDENCE_SUFFICIENT.
```yaml
source:
instrument: "European Commission CRA guidance"
provision: "practical guidance publication"
authority: "non-binding"
```
Official URL: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
Verification date: 2026-09-16

- Requirement/topic: CRA single reporting platform / ENISA ecosystem references exist, but this audit does not determine reportability or notification duty. Status: HUMAN_REVIEW_REQUIRED.
```yaml
source:
instrument: "ENISA CRA supporting material"
provision: "supporting framework and reporting ecosystem"
authority: "non-binding"
```
Official URL: https://www.enisa.europa.eu/
Verification date: 2026-09-16

### Human Review Decisions

- HUMAN_REVIEW_REQUIRED — Whether `github/gh-aw` is in CRA scope, any exclusion applies, and which economic-operator role(s) matter.
- HUMAN_REVIEW_REQUIRED — Whether any published workflow/release practices satisfy obligations for free security updates in the applicable business model.
- HUMAN_REVIEW_REQUIRED — Whether any discovered advisories or incidents ever met the Article 14 reporting threshold or active-exploitation criteria.
- HUMAN_REVIEW_REQUIRED — Whether current release and support practices are sufficient for important/critical product classes, if classification applies.

### Inaccessible or Missing Evidence

- INCOMPLETE — Internal acknowledgement tickets, response-time objectives, and escalation records were not accessible from the checkout/public metadata.
- INCOMPLETE — Internal support commitments, customer-notification templates, and Article 14 legal review records were not accessible from the checkout/public metadata.
- INCOMPLETE — Any private advisory drafts, embargo handling records, or confidential coordination notes were intentionally not accessed or reproduced.

### Human Acceptance

A non-bot reviewer SHOULD add a thumbs-up reaction only after reviewing the complete vulnerability lifecycle controls, process evidence, sampled traceability, prioritized gaps, inaccessible evidence, and human-review decisions in this record.

### Control Plane

- Correlation ID: `35111435260-322`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run: https://github.com/githubnext/gh-aw-cao/actions/runs/35111435260

> Generated by [:bug: EU CRA / Vulnerabilities](https://github.com/githubnext/gh-aw-cao/actions/runs/35112010990) · pi · gpt54 · 49.5 AIC · ⊞ 9.8K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Feu-cra-compliance-vulnerability-handling-auditor%22&type=issues)
> - [x] expires on Oct 16, 2026, 3:03 PM UTC

Contributor guide

Open the contributing guide

Research direction

Start by reading SECURITY.md, .github/workflows/codeql.yml, security-scan.yml, license-check.yml, .github/dependabot.yml, and the release workflow files identified in the audit. Review the listed gaps and sampled evidence, then determine which support-period, end-of-support, rollback, acknowledgement, and Article 14 controls need repository-visible documentation. Done means each finding has an owner and evidence source, with required legal and product decisions explicitly recorded.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, github-actions
Domain
devops, documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.