Skip to content

Commit a838d49

Browse files
fix(apm-audit): add --no-drift to skip cache-replay (v5.1.2 follow-up) (#14)
setup-only avoids overwriting tampered files but leaves the install cache empty. The 'drift' check (cache-replay) then aborts on every audit: drift: drift replay aborted: cache miss for ... --no-drift skips that replay. content-integrity still hash-checks every deployed file against the lockfile (no cache needed) so tamper is still caught. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 0d0ec6f commit a838d49

1 file changed

Lines changed: 12 additions & 8 deletions

File tree

‎.github/workflows/apm-audit.yml‎

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,16 @@ name: apm-audit
22

33
# Reusable workflow shipped by zava-agent-config for downstream APM consumers.
44
#
5-
# v5.1.2: switched apm-action to setup-only and removed `apm install` from
6-
# the audit path. Reason: install RE-DEPLOYS files from upstream, OVERWRITING
7-
# any in-PR tamper of a deployed managed file. That silently disabled drift
8-
# detection in CI (caught during D2 demo Beat 5 wiring). Audit now runs
9-
# directly against the contents of the PR, so content-integrity / drift /
10-
# unmanaged-files all see what the PR author committed.
5+
# v5.1.2: switched apm-action to setup-only + added --no-drift. Reason:
6+
# (1) `apm install` re-deploys files from upstream, OVERWRITING any in-PR
7+
# tamper of a deployed managed file -- silently disabled hash checks
8+
# in CI (caught during D2 demo Beat 5 wiring).
9+
# (2) the `drift` check itself requires a populated install cache and
10+
# ABORTS on cache miss when install hasn't run -- breaking every
11+
# audit. --no-drift skips that replay; `content-integrity` still
12+
# checks deployed-file hashes against the lockfile (cache-free) and
13+
# catches tamper. Net coverage: same set of file-tamper attacks
14+
# blocked, plus all policy checks (require / deny / unmanaged_files).
1115
#
1216
# v5.1.1: auto-detect repo apm-policy.yml override and use it as policy
1317
# source so `extends: org` actually layers (vs --policy org which loads
@@ -81,9 +85,9 @@ jobs:
8185
run: |
8286
set -euo pipefail
8387
if [ "$APM_FAIL_ON_WARN" = "true" ]; then
84-
apm audit --ci --policy "$POLICY_SOURCE" --fail-on-warning
88+
apm audit --ci --no-drift --policy "$POLICY_SOURCE" --fail-on-warning
8589
else
86-
apm audit --ci --policy "$POLICY_SOURCE"
90+
apm audit --ci --no-drift --policy "$POLICY_SOURCE"
8791
fi
8892
8993
- name: Step summary

0 commit comments

Comments
 (0)