githubnext / githubnext/gh-aw-cao
[eu-cra-compliance:vulnerability-handling-auditor] github/gh-aw CRA vulnerability handling audit
- Dominant language
- JavaScript
- Stars
- 3
- Forks
- 1
- Avg merge
- 49m
- Merged PRs (30d)
- 837
Description
`TARGET_REPO: github/gh-aw @ b1c86bd47e35ad9a575318e54dcdebcdc0a33e40`
Security intake and scanning evidence is present, and public advisories plus release automation show an active vulnerability-handling lifecycle. The main gaps are missing visible evidence for acknowledgement SLAs, supported-version/support-period inventory, end-of-support communication, and a traceable Article 14 escalation path. Several scope and conformity questions need human review.
**Action:** Security/release maintainers SHOULD review the gaps below, confirm support-period and Article 14 escalation controls, and accept this record only if each `GAP_FOUND`, `INCOMPLETE`, and `HUMAN_REVIEW_REQUIRED` row has an owner and evidence source.
## Status Summary
| Topic | Status | Evidence / gap |
| --- | --- | --- |
| Vulnerability disclosure policy and private intake | EVIDENCE_SUFFICIENT | `SECURITY.md` directs reporters to `opensource-security@github.com` and forbids public issue reporting. Verified 2026-09-16. |
| Researcher coordination and confidentiality expectation | EVIDENCE_SUFFICIENT | `SECURITY.md` requests coordinated disclosure and links GitHub Safe Harbor. Verified 2026-09-16. |
| Acknowledgement workflow / SLA | NOT_ASSESSED | No repository-visible acknowledgement timing, ownership, or ticket-state evidence located. |
| Triage ownership and severity assessment | EVIDENCE_SUFFICIENT | Published GHSA records include severity/CVSS/CWE metadata, showing a structured triage path. Verified 2026-09-16. |
| Affected-version identification | EVIDENCE_SUFFICIENT | GHSA records include vulnerable ranges and patched versions where available. Verified 2026-09-16. |
| Root-cause analysis | EVIDENCE_SUFFICIENT | GHSA descriptions include impacted files/components and remediation direction. Verified 2026-09-16. |
| Remediation decision traceability | EVIDENCE_SUFFICIENT | GHSA entries and release workflows together show patching and release promotion controls. Verified 2026-09-16. |
| Regular code/dependency scanning | EVIDENCE_SUFFICIENT | `.github/workflows/codeql.yml`, `security-scan.yml`, `.github/dependabot.yml`, and `license-check.yml` show recurring scanning/monitoring. Verified 2026-09-16. |
| Component inventory / SBOM | EVIDENCE_SUFFICIENT | `SECURITY.md` states SBOM generation on every release in SPDX and CycloneDX. Verified 2026-09-16. |
| Timely security-fix distribution | EVIDENCE_SUFFICIENT | Recent releases exist; `release.md` / `release.lock.yml` automate release, SBOM attachment, and latest promotion controls. Verified 2026-09-16. |
| Free security updates where required | HUMAN_REVIEW_REQUIRED | Public OSS repo evidence suggests updates are published, but CRA role/scope and applicable duty need explicit human legal/product review. |
| Release notes / customer communication | EVIDENCE_SUFFICIENT | Release workflow exists and public GitHub releases are published; exact security-communication practice per incident not fully sampled. |
| Rollback or mitigation path | NOT_ASSESSED | No concise repository-visible rollback/mitigation procedure for security releases was confirmed in sampled evidence. |
| Coordinated upstream/downstream disclosure | EVIDENCE_SUFFICIENT | `SECURITY.md` requests coordinated disclosure; GHSA usage indicates downstream advisory publication capability. |
| CNA / CVE practice where applicable | EVIDENCE_SUFFICIENT | Repository uses GitHub Security Advisories (GHSA). CVE issuance applicability remains context dependent. |
| Handling withheld details | NOT_ASSESSED | No explicit public rule for temporary detail withholding located in sampled evidence. |
| Supported-version inventory | GAP_FOUND | No clear repository-visible supported-version matrix or policy was found. |
| Support period definition | GAP_FOUND | No clear support-period/EOS policy was found in sampled repository files. |
| End-of-support communication | GAP_FOUND | No clear EOS communication procedure was found in sampled repository files. |
| Timestamp preservation across lifecycle | EVIDENCE_SUFFICIENT | GitHub advisories/releases/commits preserve created, updated, published, and release timestamps. Verified 2026-09-16. |
| Article 14 escalation path linkage | GAP_FOUND | No repository-visible pointer to an internal CRA Article 14 assessment/escalation decision path was found. |
## Lifecycle Control Matrix
| Control claim | Status | Source / URL | Verification date |
| --- | --- | --- | --- |
| Private vulnerability intake channel is published | EVIDENCE_SUFFICIENT | `target/SECURITY.md`; https://github.com/github/gh-aw/blob/main/SECURITY.md | 2026-09-16 |
| Public reporting is discouraged for vulnerabilities | EVIDENCE_SUFFICIENT | `target/SECURITY.md`; https://github.com/github/gh-aw/blob/main/SECURITY.md | 2026-09-16 |
| Dependency monitoring is scheduled | EVIDENCE_SUFFICIENT | `target/.github/dependabot.yml`; https://github.com/github/gh-aw/blob/main/.github/dependabot.yml | 2026-09-16 |
| Code scanning is scheduled | EVIDENCE_SUFFICIENT | `target/.github/workflows/codeql.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/codeql.yml | 2026-09-16 |
| Security scanning is scheduled | EVIDENCE_SUFFICIENT | `target/.github/workflows/security-scan.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/security-scan.yml | 2026-09-16 |
| License/composition checking is automated | EVIDENCE_SUFFICIENT | `target/.github/workflows/license-check.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/license-check.yml | 2026-09-16 |
| Security advisories are published with version impact metadata | EVIDENCE_SUFFICIENT | GitHub advisories API for `github/gh-aw`; https://github.com/github/gh-aw/security/advisories | 2026-09-16 |
| Release pipeline contains security-sensitive controls | EVIDENCE_SUFFICIENT | `target/.github/workflows/release.md` and `release.lock.yml`; https://github.com/github/gh-aw/blob/main/.github/workflows/release.md | 2026-09-16 |
| Support-period policy is repository-visible | GAP_FOUND | Topic searched in `README.md`, `SECURITY.md`, workflows, and sampled docs; no decisive policy found | 2026-09-16 |
| Article 14 escalation reference is repository-visible | GAP_FOUND | Topic searched in sampled repository materials; no decisive reference found | 2026-09-16 |
## Sampled Traceability
- EVIDENCE_SUFFICIENT: Public GHSA records include `published_at`, `updated_at`, severity, CWE/CVSS, affected package/version range, and patched version fields where available.
- EVIDENCE_SUFFICIENT: Latest observed releases are public prereleases (`v0.89.15`, `v0.89.13`, `v0.89.12`, `v0.89.11`, `v0.89.10`); repository main branch commit date observed as `2026-09-16T11:39:49Z`.
- EVIDENCE_SUFFICIENT: `docs/security-findings-2026-01-19.md` shows documented scan follow-up, but it is a point-in-time artifact rather than a stable support-policy control.
### Prioritized Gaps
1. GAP_FOUND — Publish a concise supported-version and support-period policy for releases/users.
2. GAP_FOUND — Document how end-of-support is communicated and how vulnerability handling continues for supported versions.
3. GAP_FOUND — Add a repository-visible pointer to the internal Article 14 escalation decision path without deciding reportability in public.
4. NOT_ASSESSED — Preserve or expose acknowledgement/coordination timestamps in a durable process record accessible to reviewers.
5. NOT_ASSESSED — Document whether and how security-release rollback/mitigation guidance is communicated when fixes cannot ship immediately.
### What's working
The repository has a nice security baseline: public intake instructions, scheduled CodeQL/gosec/govulncheck/dependency scanning, SBOM generation, and published GHSA records already provide a strong evidence spine for reviewers.
### Regulatory Findings
- Requirement/topic: vulnerabilities and security updates process evidence. Status: EVIDENCE_SUFFICIENT for several operational controls, but not a legal conformity conclusion.
```yaml
source:
instrument: "Regulation (EU) 2024/2847"
provision: "Article 13; Article 14"
authority: "binding"
```
Official URL: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Verification date: 2026-09-16
- Requirement/topic: baseline CRA dates were checked against official sources. Status: EVIDENCE_SUFFICIENT for 10 December 2024, 11 June 2026, 11 September 2026, and 11 December 2027; no discrepancy observed in sampled official sources.
```yaml
source:
instrument: "Regulation (EU) 2024/2847"
provision: "entry into force and application timeline"
authority: "binding"
```
Official URL: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Verification date: 2026-09-16
- Requirement/topic: Commission CRA guidance dated 27 July 2026 exists, but is non-binding. Status: EVIDENCE_SUFFICIENT.
```yaml
source:
instrument: "European Commission CRA guidance"
provision: "practical guidance publication"
authority: "non-binding"
```
Official URL: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
Verification date: 2026-09-16
- Requirement/topic: CRA single reporting platform / ENISA ecosystem references exist, but this audit does not determine reportability or notification duty. Status: HUMAN_REVIEW_REQUIRED.
```yaml
source:
instrument: "ENISA CRA supporting material"
provision: "supporting framework and reporting ecosystem"
authority: "non-binding"
```
Official URL: https://www.enisa.europa.eu/
Verification date: 2026-09-16
### Human Review Decisions
- HUMAN_REVIEW_REQUIRED — Whether `github/gh-aw` is in CRA scope, any exclusion applies, and which economic-operator role(s) matter.
- HUMAN_REVIEW_REQUIRED — Whether any published workflow/release practices satisfy obligations for free security updates in the applicable business model.
- HUMAN_REVIEW_REQUIRED — Whether any discovered advisories or incidents ever met the Article 14 reporting threshold or active-exploitation criteria.
- HUMAN_REVIEW_REQUIRED — Whether current release and support practices are sufficient for important/critical product classes, if classification applies.
### Inaccessible or Missing Evidence
- INCOMPLETE — Internal acknowledgement tickets, response-time objectives, and escalation records were not accessible from the checkout/public metadata.
- INCOMPLETE — Internal support commitments, customer-notification templates, and Article 14 legal review records were not accessible from the checkout/public metadata.
- INCOMPLETE — Any private advisory drafts, embargo handling records, or confidential coordination notes were intentionally not accessed or reproduced.
### Human Acceptance
A non-bot reviewer SHOULD add a thumbs-up reaction only after reviewing the complete vulnerability lifecycle controls, process evidence, sampled traceability, prioritized gaps, inaccessible evidence, and human-review decisions in this record.
### Control Plane
- Correlation ID: `35111435260-322`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run: https://github.com/githubnext/gh-aw-cao/actions/runs/35111435260
> Generated by [:bug: EU CRA / Vulnerabilities](https://github.com/githubnext/gh-aw-cao/actions/runs/35112010990) · pi · gpt54 · 49.5 AIC · ⊞ 9.8K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Feu-cra-compliance-vulnerability-handling-auditor%22&type=issues)
> - [x] expires on Oct 16, 2026, 3:03 PM UTC
Contributor guide
Research direction
Start by reading SECURITY.md, .github/workflows/codeql.yml, security-scan.yml, license-check.yml, .github/dependabot.yml, and the release workflow files identified in the audit. Review the listed gaps and sampled evidence, then determine which support-period, end-of-support, rollback, acknowledgement, and Article 14 controls need repository-visible documentation. Done means each finding has an owner and evidence source, with required legal and product decisions explicitly recorded.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, github-actions
- Domain
- devops, documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100