Skip to content

sodejm/patch-security-review

v0.1.0PolyForm-Noncommercial-1.0.0

Bounded offline security review of an immutable Git commit pair.

COPS Patch Security Review

This offline workbench pins a local Git base and head to full commit IDs, reads a bounded patch and source blobs, and records changed entrypoints and candidate source-to-sink paths. It does not execute reviewed repository code.

python3 plugins/vulnerability-management/patch-security-review/scripts/review.py review --repo /path/to/repo --base BASE --head HEAD

The report separates observed facts, plausible scenarios, unknowns, and validated findings. Rule matches are never automatically validated. Python rules inspect calls to os.system, eval, exec, and shell-enabled subprocess functions; JavaScript rules inspect route markers and dynamic execution calls. Other languages, cross-function flow, sanitizers, and many sinks remain unknown or uncovered. A clean report is not a safety verdict.

An analyst can record a candidate validation with review.py validate --report and --candidate-id, --analyst, --preconditions, and --disconfirming-evidence. These fields are self-recorded assertions, not trusted identity or approval attestation. Reports print to stdout by default; use --output only in an analyst-owned private directory. The command creates a new mode-0600 file and refuses replacement.

Limits: 1 MiB patch, 100 changed files, 256 KiB per source file, 100 candidates, and 2 MiB report. Binary patches and oversized source are rejected. The workbench uses local Git only. It has no network calls or runtime dependency beyond Python 3.11+ and Git. Concurrent untrusted mutation of the local repository or output tree needs a separate deployment boundary.