Skip to content

Require evidence before reporting red-team security findings - #67542

Merged
pelikhan merged 2 commits into
mainfrom
copilot/security-2026-10-10-fix-red-team-findings
Oct 11, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/security-2026-10-10-fix-red-team-findings

Conversation

Copilot AI commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

The daily scan reported 14 SECRET_EXFIL findings without demonstrating secret-to-network data flow; cited lines included imports and test scaffolding. Heuristic matches could be treated as confirmed findings without consistent validation across scan variants.

  • Candidate classification: Regex matches and high-entropy results are treated as leads, not confirmed findings.
  • Evidence gate: All variants verify cited code; SECRET_EXFIL requires tracing the same sensitive value from source to outbound sink. Unverified candidates are discarded.
  • Reporting: Issue summaries identify findings as validated.
verified secret source → outbound sink  ⇒  report SECRET_EXFIL
otherwise                           ⇒  dismiss candidate

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix security issues from red team findings Require evidence before reporting red-team security findings Oct 11, 2026
Copilot AI requested a review from pelikhan October 11, 2026 00:31
@pelikhan
pelikhan marked this pull request as ready for review October 11, 2026 00:57
Copilot AI balanced review requested due to automatic review settings October 11, 2026 00:57
@pelikhan
pelikhan merged commit 79fc81c into main Oct 11, 2026
3 checks passed
@pelikhan
pelikhan deleted the copilot/security-2026-10-10-fix-red-team-findings branch October 11, 2026 00:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Candidate promotion and dismissed-candidate reporting can still produce inaccurate results.

1 open finding
What changed in this PR

Adds an evidence gate so heuristic security matches are validated before reporting.

Changes:

  • Reclassifies secret-exfiltration and entropy matches as candidates.
  • Requires source-to-sink verification and records dismissals.
  • Labels issue summaries as validated findings.

Security review found two reporting-path gaps; scanners were not executed in this review environment.

File Description
.github/​workflows/​daily-security-red-team.md Adds candidate validation and reporting rules.
.github/​workflows/​daily-security-red-team.lock.yml Updates generated workflow hashes.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

1. Verify that each cited path exists and that its line number is in range and points to the behavior being reported. Do not treat imports, comments, type declarations, or test fixtures alone as evidence of a production vulnerability.
2. Treat regex matches, suspicious keywords, entropy scores, and long encoded strings as leads only. A heuristic match does not establish malicious behavior.
3. For any `SECRET_EXFIL_CANDIDATE`, identify the sensitive value source and the outbound network sink, then trace the same value from source to sink. Cite the exact source and sink lines and explain the data flow. An environment-variable read, a network call, or high entropy on its own is insufficient. Promote the candidate to `SECRET_EXFIL` only when this path is verified; otherwise remove it from `FINDINGS[]` and record the reason in `$CACHE_DIR/dismissed-findings-${TIMESTAMP}.json`.
4. Apply the same evidence standard to other finding types: retain only findings supported by the cited code and its behavior. If a candidate cannot be verified, do not report it as a confirmed issue.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🚨 [SECURITY] Security Red Team Findings - 2026-10-10

3 participants