Skip to content

Add/amend .security/ context bundle - #79

Merged
sfc-gh-vpalekar merged 4 commits into
snowflakedb:mainfrom
sfc-gh-eukim:security-context-bundle
Oct 2, 2026
Merged

sfc-gh-vpalekar merged 4 commits into
snowflakedb:mainfrom
sfc-gh-eukim:security-context-bundle

Conversation

@sfc-gh-eukim

Copy link
Copy Markdown
Contributor

Port of snowflake-eng/mz-snowflake-telemetry-python#1 (same .security/ context bundle, unchanged) so it can land in the upstream repo.


Revised the bundle to resolve the two BLOCKS findings only, leaving all SUPPORTED content and the rest of the manifest unchanged.

  1. trust-boundaries.md (exemption finding): The 'SnowflakeTraceIdGenerator' section previously described the non-cryptographic PRNG used for trace-ID generation and then added a self-labeled 'plain fact' conclusion ('not secrets or authorization tokens anywhere in this repository or its OpenTelemetry SDK dependency') that functioned as an argument pre-emptively dismissing a weak-randomness finding. Removed that dismissive conclusion and the judgment-laden section heading ('...is a correlation identifier, not an access-control token'), keeping only the verifiable implementation fact (4-byte 'minutes since the epoch' + 12 bytes from random.getrandbits(96), the stdlib's non-cryptographic PRNG, not secrets), with its existing file citation (src/snowflake/telemetry/trace/init.py) intact. No control was weakened -- the underlying weak-randomness fact is still fully recorded, just without the added argument disposing of its significance.

  2. architecture.md (contradicted claim): The claim that the regex socket|urllib|requests|http\.client|grpc|subprocess|os\.system|open\( 'matches only comment lines' at two specific citations (src/snowflake/telemetry/_internal/serialize/init.py:16 and .../opentelemetry/exporter/otlp/proto/common/version/init.py:17) was false. I independently reran the exact regex against src/ with ripgrep and got zero matches (confirmed also with grep -E), and inspected the two cited lines directly -- neither contains any of the listed terms (one is a protobuf-docs URL comment, the other an upstream-license URL comment). Corrected the text to state that the search (via both rg and Python's re module) returns zero matches anywhere under src/, removed the incorrect line citations, and added a separately-verified broader search (import socket|import subprocess|import requests|urllib|grpc|os\.system|\bopen\(, also zero matches) as corroborating evidence for the 'nothing internet-facing' conclusion, per the judge's suggested correction.

No other documents (threat-model.md, secure-coding.md) or unflagged passages were modified, since all other cited claims were independently verified as SUPPORTED (PYPI_API_TOKEN scoping, INV-1 through INV-4 mechanisms/line citations, and the reserved-log-attribute test behavior all matched the repository exactly).

Judge verdicts

Exemption judge

  • BLOCKS .security/trust-boundaries.md: "Combined with the absence of any socket/HTTP/file-write call anywhere in src/ (see architecture.md), a finding that assumes this repository's code sends telemetry data to a specific network destination, an S3 bucket, or a database is describing the embedding application's writer implementation — which lives outside this repository — not code that exists here." — Pre-classifies an entire category of future findings as automatically misattributed/out-of-scope for this repo, functioning as a built-in dismissal rationale rather than a statement of what currently exists — a disposition wearing an architecture-fact's clothes.
  • NOTE .security/trust-boundaries.md: "Neither the Jenkins job's configuration nor what consumes packages from that channel is visible from this repository." — Names a specific unverifiable area (Jenkins build config, downstream conda consumers) rather than simply stating what is verified, biasing the reader to treat that named blind spot as settled rather than open.
  • NOTE .security/threat-model.md: "Holding — covers only "the committed code matches the pinned tag's current content", not "that tag's content is safe"; see the systems-table row above and the gap this leaves open" — Explicitly names an uncertainty ("the gap this leaves open") about upstream content safety rather than only stating what is verified.
  • NOTE .security/threat-model.md: "Holding — same partial-coverage caveat as INV-2" — Repeats/points at the same named gap as INV-2 rather than stating only what the control verifies.
  • NOTE .security/secure-coding.md: "it proves the committed code matches what the pinned ref currently produces. It does not prove the pinned ref's content is safe, and none of the three refs pinned in this repository's scripts or workflows (v1.7.0, v1.38.0, and the third-party GitHub Actions used in the workflow files under .github/workflows/) are pinned to an immutable commit SHA" — States what is verified but also explicitly foregrounds an unresolved uncertainty (upstream ref mutability/safety) rather than remaining silent on it, drawing reader attention to that specific unverified point.

Unsupported-claim judge

No findings.

@sfc-gh-eukim
sfc-gh-eukim marked this pull request as ready for review October 2, 2026 06:46
@sfc-gh-eukim
sfc-gh-eukim requested a review from a team as a code owner October 2, 2026 06:46

@snowflake-security-bot snowflake-security-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Snowflake Security Review

Security grade: A — Passed ✅

This PR was classified as LOW risk by the automated pre-screen.

sfc-gh-eukim and others added 2 commits October 2, 2026 17:12
…l Observability

Update Jira routing (area, component) and product_owner for this
SecurityContext to the External Observability team.

Co-authored-by: Cursor <cursoragent@cursor.com>
Aligns the owner contact with the External Observability Jira routing.

Co-authored-by: Cursor <cursoragent@cursor.com>

@snowflake-security-bot snowflake-security-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Snowflake Security Review

Security grade: A — Passed ✅

This PR was classified as LOW risk by the automated pre-screen.

Remove jira_area, jira_component, and product_owner (internal Jira
taxonomy and a personal email) and the internal DL from the owner
annotation (restored to the public GitHub team). Internal routing lives
in the internal mirror copy of this bundle. metadata.name and the
documents list are unchanged.

Co-authored-by: Cursor <cursoragent@cursor.com>

@snowflake-security-bot snowflake-security-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Snowflake Security Review

Security grade: A — Passed ✅

This PR was classified as LOW risk by the automated pre-screen.

@sfc-gh-vpalekar
sfc-gh-vpalekar merged commit 204084b into snowflakedb:main Oct 2, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants