Skip to content

fix(security): preserve #661 accessibility and Jackson owner delta - #662

Open
seonghobae wants to merge 31 commits into
mainfrom
codex/clearfolio-661-preserved-20261001
Open

seonghobae wants to merge 31 commits into
mainfrom
codex/clearfolio-661-preserved-20261001

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Verified successor for #661

This Ready successor preserves every valid #661 delta after the original writer repeatedly restored a vulnerable predecessor tree. Ready is review admission only; it is not merge authority.

  • Exact head: b1905cfb4b6500eb048f9829648e75096ed5e666
  • Exact tree: 12c804cec038e60e51df730abe8e9b6610976f3e
  • Carries the required-field accessibility controller/test unchanged.
  • Carries canonical owner fix(security): bump Jackson from 2.22.1 to 2.22.3 #503 completely: Jackson 2.22.3, generated SBOM hashes and dependency edges, regenerated attribution, POM/SBOM/attribution regression contracts, expired OSV-exception removal, CHANGELOG, and product-gap RCA.
  • Preserves the repeated concurrent rollback commits in ordinary history; the repair restores only the proven owner paths.
  • Carries fix(a11y): expose required document field text #663's stricter full-label response regression and records its complete-carryover boundary; the production UI blob was already byte-identical.
  • Completeness proof: compared with first validated integration 7d0e62bac287e590df8451950a0c90952ed76b36, only docs/product-technical-gap-baseline.md differs. Compared with original UI head 600995328dc03d53a63e7b67d3b8c9501f3baa17, exactly the eight canonical owner paths differ.
  • Original 🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가 #661 remains open Draft as evidence. It is not closed or treated as completed.

Exact-head evidence:

  • Security 36926553916: GREEN
  • CI 36926553965: GREEN
  • SAST 36926554001: GREEN
  • fuzz 36926553970: all three shards GREEN
  • CodeQL 36926554506: terminal RED only because all four compatibility shards read VERDICT_STATE=pending; coordinator job 110591410665 successfully validated the live head/base/source, obtained OIDC and the repository-scoped App token, and published the exact codeql-scan-v2 request
  • CodeQL failure boundary: Python job 110588179436 and its sibling shards failed at Release runner or enforce current-head CodeQL verdict; no authenticated terminal receipt or exact-job continuation followed
  • canonical workflow owner: CodeQL dispatch terminal status publication remains unproven across repositories .github#1929, with repair PR fix(codeql): wake required jobs with the exchanged target app token .github#2040 retained Draft while its mutable prerequisite chain is completed
  • independent APPROVED review: absent

This is a central terminal-publication/continuation blocker, not a clearfolio source or SARIF finding. Ready is preserved for review admission; merge remains HOLD until the authenticated terminal CodeQL verdict and independent approval exist. No manual rerun, no-op commit, synthetic status, state toggle, bypass, or predecessor evidence transfer is authorized.

dependabot Bot and others added 28 commits August 24, 2026 00:12
Bumps `jackson-bom.version` from 2.22.1 to 2.22.2.

Updates `com.fasterxml.jackson:jackson-bom` from 2.22.1 to 2.22.2
- [Commits](FasterXML/jackson-bom@jackson-bom-2.22.1...jackson-bom-2.22.2)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.22.1 to 2.22.2
- [Commits](https://github.com/FasterXML/jackson/commits)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson:jackson-bom
  dependency-version: 2.22.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
Preserve the required-field accessibility delta while integrating the complete Jackson 2.22.3 owner repair, SBOM, attribution, RED contracts, expired-exception removal, CHANGELOG, and product-gap evidence through ordinary two-parent ancestry.
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
… revert

Preserve the concurrent commit in ordinary history while restoring the complete #503 Jackson 2.22.3, SBOM, attribution, regression-contract, expired-exception removal, CHANGELOG, and product-gap evidence set. Trivy run 36829505965 on 5d27441 reproduced CVE-2026-68497, CVE-2026-91776, CVE-2026-91777, CVE-2026-19032, and CVE-2026-83557.
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
Keep the second concurrent commit in ordinary history while restoring the same complete #503 Jackson 2.22.3 owner tree. Exact Security run 36829843477 failed again after the repeated eight-path downgrade.
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
Preserve the third concurrent commit and the expanded RCA baseline while restoring the remaining seven owner paths and deleting the expired OSV exception.
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
Preserve the fourth concurrent commit and restore the canonical Jackson 2.22.3 owner tree plus the documented concurrency RCA.
💡 변경 내용: "Document" 라벨을 "Document (required)"로 변경하고 span 태그로 감쌈
🎯 이유: 웹 접근성 향상을 위해 시각적 표시(*) 대신 스크린 리더가 읽을 수 있는 텍스트가 필요함.
📸 전후: [해당사항 없음]
♿ 접근성: 필수 항목임을 스크린 리더가 명확하게 인지할 수 있도록 개선됨
Preserve the fifth concurrent commit in ordinary history, restore the complete canonical Jackson 2.22.3 owner tree and RCA, and establish the verified successor lineage after repeated writes made the original branch unstable.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: ed3e5fce-dc08-41b3-82e2-422d9fb85e5b

📥 Commits

Reviewing files that changed from the base of the PR and between 06633a2 and 0a51f00.

📒 Files selected for processing (11)
  • .jules/palette.md
  • CHANGELOG.md
  • docs/legal/2026-07-03-third-party-attribution.md
  • docs/product-technical-gap-baseline.md
  • docs/qa/evidence/2026-07-02-krw2b-sale-readiness/sbom-cyclonedx.json
  • osv-scanner.toml
  • pom.xml
  • scripts/test_render_third_party_attribution.py
  • src/main/java/com/clearfolio/viewer/controller/ViewerUiController.java
  • src/test/java/com/clearfolio/viewer/config/DependencyPolicyTest.java
  • src/test/java/com/clearfolio/viewer/controller/ViewerUiRequiredFieldAccessibilityTest.java
💤 Files with no reviewable changes (1)
  • osv-scanner.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Jackson BOM을 2.22.3으로 갱신하고 관련 취약점 예외, SBOM, 제3자 고지 및 버전 검증을 업데이트했습니다. 파일 입력 레이블에 “(required)”를 표시하고 관련 테스트와 작성 지침을 추가했습니다.

Changes

Jackson 보안 업데이트

Layer / File(s) Summary
Jackson BOM과 취약점 예외 갱신
pom.xml, osv-scanner.toml, src/test/java/com/clearfolio/viewer/config/DependencyPolicyTest.java
BOM 버전을 2.22.3으로 변경하고 OSV 무시 항목을 삭제했습니다. 테스트에서 BOM 버전을 확인합니다.
공급망 증거와 버전 일치 검증
scripts/test_render_third_party_attribution.py, docs/qa/evidence/2026-07-02-krw2b-sale-readiness/sbom-cyclonedx.json, docs/legal/2026-07-03-third-party-attribution.md, CHANGELOG.md, docs/product-technical-gap-baseline.md
SBOM과 제3자 고지의 Jackson 버전을 2.22.3으로 갱신했습니다. POM, SBOM, 고지 간 버전 일치 검증을 추가하고 보안 변경 기록과 기술 기준선 문서를 업데이트했습니다.

필수 입력 접근성 표시

Layer / File(s) Summary
문서 입력 레이블과 접근성 검증
src/main/java/com/clearfolio/viewer/controller/ViewerUiController.java, src/test/java/com/clearfolio/viewer/controller/ViewerUiRequiredFieldAccessibilityTest.java, .jules/palette.md
파일 입력 레이블을 “Document (required)”로 바꾸고 필수 텍스트를 span으로 감쌌습니다. 컨트롤러 응답의 상태, 콘텐츠 타입 및 레이블을 검증하는 테스트와 작성 지침을 추가했습니다.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 0a51f

No concrete merge-blocking defect is identified. The dependency records and required-file label are aligned, but merging should still wait for the required current-head checks and independent approval.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0a51f

The reviewed changes strengthen dependency-version consistency without demonstrating new attacker reachability or increased privileges. Production dependency resolution and completed validation of the assessed revision remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated dependency-policy scope is the viewer application's managed Jackson modules and associated repository checks. The supplied runtime evidence does not establish attacker-controlled Jackson deserialization, affected tenants, or deployed environments.

Trust Boundaries and Controls

  • observed — The script-check CI job checks out and verifies the requested head revision, disables persisted checkout credentials, installs hash-required test dependencies, and runs the repository script tests. Workflow permissions specify read-only repository contents. These controls describe the inspected configuration, not a successful execution.
  • inferred — The new consistency checks consume PR-controlled repository files within the existing test process. They do not accept service-request inputs or caller-selected paths, and no new production authority transition is demonstrated.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 45.45% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 11 functions across 4 files. (6 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 #661 접근성 변경 보존과 Jackson 보안 변경을 명확하게 요약합니다. 실제 변경 사항과 주요 목적에 부합합니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 45.45% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 11 functions across 4 files. (6 skipped: 6 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Collaborator Author

Exact-head successor verification

Current head 0a51f00c2e0cff8e55ac1f3d044d468aa0661797 is stable and mergeable.

No APPROVED review exists. No force update, destructive rebase, gate weakening, manual rerun, self-approval, predecessor close, or merge was performed.

Copy link
Copy Markdown
Collaborator Author

Exact-head carryover verification

Current Ready head b1905cfb4b6500eb048f9829648e75096ed5e666 is open and mechanically mergeable.

Complete-carryover proof for #663:

Exact-head results:

  • CI 36926553965: GREEN (Maven tests, buyer-readiness scripts, merge compatibility);
  • Security 36926553916: GREEN (Trivy, OSV, dependency-review, Scorecard);
  • SAST 36926554001: GREEN;
  • fuzz 36926553970: all three shards GREEN;
  • CodeQL 36926554506: queued, therefore not passing evidence;
  • current-head APPROVED review: absent.

Ready is review admission only. Merge remains HOLD. No Force Push, destructive rebase, bypass, manual rerun, or synthetic wake event was used.

Copy link
Copy Markdown
Collaborator Author

Current-head CodeQL RCA

Exact Ready head b1905cfb4b6500eb048f9829648e75096ed5e666 remains open and mechanically mergeable. CI 36926553965, Security 36926553916, SAST 36926554001, and fuzz 36926553970 are terminal GREEN; there are zero review submissions and zero review threads.

CodeQL run 36926554506 is terminal RED at the central continuation boundary:

  • all four compatibility shards reached DISPATCH_OUTCOME=success, VERDICT_STATE=pending;
  • Python job 110588179436 failed only at Release runner or enforce current-head CodeQL verdict with “The dispatch workflow will rerun this exact failed CodeQL job after publishing its terminal verdict”;
  • coordinator job 110591410665 successfully revalidated the live PR/head/base/source, obtained OIDC and the repository-scoped App token, bound every language to its exact job ID, and submitted codeql-scan-v2;
  • no authenticated terminal receipt or exact-job continuation followed.

This is not a clearfolio source or SARIF finding. The exact evidence is routed to canonical owner ContextualWisdomLab/.github#1929; repair remains owned by ContextualWisdomLab/.github#2040 and its prerequisite chain. Ready is preserved for review admission. Merge remains HOLD; no manual rerun, no-op push, synthetic status, state toggle, bypass, or predecessor evidence transfer was used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant