Skip to content

docs(adr): accept ADR-0043; record the CodeQL findings its zod bump surfaced - #247

Merged
mbeacom merged 1 commit into
mainfrom
docs/accept-adr-0043
Sep 29, 2026
Merged

mbeacom merged 1 commit into
mainfrom
docs/accept-adr-0043

Conversation

@mbeacom

@mbeacom mbeacom commented Sep 28, 2026

Copy link
Copy Markdown
Owner

What and why

ADR-0043 is now accepted (ratifiedBy: @mbeacom). All five action items were already done, including the post-deploy check that both served schema versions have the right SHA-256.

One new Consequences bullet records how CodeQL alerts #9 and #10 (js/bad-code-sanitization) were handled. #241's zod 4.6.5 bump surfaced them.

  • Where they point: zod's object fast path, Doc.compile(), which builds a parser with new Function. The flagged code is bundled into packages/ci/dist/index.js and packages/ci/dist/queue-action.js.
  • The flagged value is JSON.stringify of a zod object-schema key. Every such key is a field name from adrkit's own fixed schemas; no ADR, PR or event content can become one. z.record keys don't go through this code, and adrkit never calls z.compile.
  • The query's worries don't apply here. It checks for </script> and the U+2028/U+2029 line separators. These values only land inside JS string literals run on Node, where </script> is harmless and those two characters have been legal since ES2019.
  • So both are false positives. They get dismissed rather than excluded, because codeql.yml scans the committed bundles on purpose. The bullet says to re-check that the schema keys are still fixed if a later zod bump raises the alerts again.

The dismissals themselves happen through the GitHub API, not in this PR. The bullet describes them as done ("are dismissed"), so do them before this merges.

MANIFEST.md regenerated with bun run emit:manifest. ADR-0043's decision text is unchanged; the edits are status, provenance and the Consequences bullet.

Checklist

  • DCO signed off.
  • adr lint passes (43 records), MANIFEST.md is regenerated, and check:stale-refs passes.
  • Schema / dist / tests: n/a (two documents only)

Notes for reviewers

  • No z.config({ jitless: true }) hardening. It turns off the new Function call at runtime, but the code stays in the bundle, so the alerts would stay open. It would be a separate hardening decision, not a fix for these alerts.
  • No paths-ignore for packages/ci/dist/**: those bundles are what runs in consumers' CI, and the workflow says it scans them on purpose.

…urfaced

ADR-0043: status accepted, ratifiedBy @mbeacom. All five action items were
already complete, including the post-deploy check of both served schema
versions.

Consequences gains a note on CodeQL alerts 9 and 10
(js/bad-code-sanitization in packages/ci/dist/index.js and
queue-action.js). Both point at zod 4.6's object fast path, Doc.compile(),
which #241's bump brought into the bundles. The flagged value is
JSON.stringify of a zod shape key. Every such key is a field name from
adrkit's static schemas, never corpus or PR content, and it only ever
sits in a string-literal position in code run on Node. So both alerts are
false positives. They are to be dismissed rather than excluded, because
codeql.yml scans the committed bundles on purpose.

MANIFEST.md regenerated by `bun run emit:manifest`.

Signed-off-by: Mark Beacom <m@beacom.dev>
Copilot AI balanced review requested due to automatic review settings September 28, 2026 21:50
@mbeacom mbeacom self-assigned this Sep 28, 2026
@mbeacom mbeacom added the documentation Improvements or additions to documentation label Sep 28, 2026
@github-actions

Copy link
Copy Markdown

Decisions governing this change

  • 0001 — Record architecture decisions as versioned markdown in git
    • via path: docs/adr/**

Active proposals touching this change

These are not yet ratified and do not bind this change:

  • 0040 — Keep derived surfaces in lockstep with three mechanisms matched to three classes of drift (proposed)
    • via path: MANIFEST.md

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The documentation is internally consistent, but the claimed security-alert dismissals require verification by someone with code-scanning access.

Review effort: Balanced
Findings: None

What changed in this PR

Accepts ADR-0043 and documents why two Zod-related CodeQL findings are false positives.

Changes:

  • Marks ADR-0043 accepted with human ratification.
  • Records CodeQL analysis, dismissal rationale, and completed deployment verification.
  • Regenerates the ADR inventory.

The alert dismissal state could not be verified because the GitHub API denied access.

File Description
MANIFEST.md Updates generated status counts and ADR-0043’s status.
docs/​adr/​0043-…md Records acceptance, ratification, CodeQL consequences, and completed actions.

@mbeacom
mbeacom merged commit 9934bf2 into main Sep 29, 2026
24 checks passed
@mbeacom
mbeacom deleted the docs/accept-adr-0043 branch September 29, 2026 12:19
@mbeacom mbeacom added the adr label Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

adr documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants