Skip to content

refactor(release): remove unreachable DER parser guards - #399

Merged
mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/remove-unreachable-der-guards
Aug 14, 2026
Merged

refactor(release): remove unreachable DER parser guards#399
mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/remove-unreachable-der-guards

Conversation

@mldangelo-oai

Copy link
Copy Markdown
Collaborator

Summary

Remove unreachable DER parser checks and a test that snapshots their source text.

Changes

  • Rely on the existing DER element parser, which already guarantees cursor advancement and enforces the parent boundary.
  • Delete the source-regex test while retaining behavioral malformed-certificate and provenance coverage.

Testing

  • bun test tests-ts/release-automation.test.ts tests-ts/package-provenance.test.ts --timeout 30000 — passed.
  • pnpm run types — passed.
  • prettier --check scripts/release-automation.mjs tests-ts/release-automation.test.ts — passed.
  • git diff --check — passed.

Risk and rollout

Every accepted DER element consumes its tag and length bytes, and the parser rejects elements extending beyond their parent. Existing malformed-certificate, signing, and package-provenance tests continue to exercise the actual verification behavior.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

Reviewed commit: 649a265650

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

Security review completed. No security issues were found in this pull request.

Reviewed commit: 649a265650

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@zcrab-oai zcrab-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Removes unreachable DER parser guards while preserving malformed certificate and release-signing verification.

@mldangelo-oai
mldangelo-oai merged commit bfb19ef into main Aug 14, 2026
34 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/remove-unreachable-der-guards branch August 14, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants