From f220223947af08ba331f141c7d4c18a919451dbf Mon Sep 17 00:00:00 2001 From: robert Date: Tue, 4 Aug 2026 10:47:16 +0300 Subject: [PATCH] Update Claude scanning --- .github/workflows/claude-full-security-scan.yml | 2 +- .github/workflows/claude-pr-security-review.yml | 2 +- resources/specs/claude-security-scan-instructions.md | 9 +++++++++ 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/.github/workflows/claude-full-security-scan.yml b/.github/workflows/claude-full-security-scan.yml index f7455af7..b569b192 100644 --- a/.github/workflows/claude-full-security-scan.yml +++ b/.github/workflows/claude-full-security-scan.yml @@ -96,7 +96,7 @@ jobs: claude_args: | --max-turns 20 --allowedTools "Read,Glob,Grep,Bash(git:*),Bash(find:*),Bash(grep:*),Bash(sed:*),Bash(cat:*)" - --model claude-opus-4-8 + --model claude-opus-5 - name: Prepare private security scan outputs if: always() && steps.claude_scan.outputs.execution_file != '' diff --git a/.github/workflows/claude-pr-security-review.yml b/.github/workflows/claude-pr-security-review.yml index 56d6b2a0..12bdee64 100644 --- a/.github/workflows/claude-pr-security-review.yml +++ b/.github/workflows/claude-pr-security-review.yml @@ -111,4 +111,4 @@ jobs: claude_args: | --allowedTools "Read,Bash(cat:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr comment:*)" - --model claude-opus-4-8 + --model claude-opus-5 diff --git a/resources/specs/claude-security-scan-instructions.md b/resources/specs/claude-security-scan-instructions.md index bf6d6631..68f645f0 100644 --- a/resources/specs/claude-security-scan-instructions.md +++ b/resources/specs/claude-security-scan-instructions.md @@ -19,6 +19,15 @@ # SECURITY CATEGORIES TO EXAMINE +## Mandatory High-Risk Coverage: Built-In TLS + +The built-in TLS implementation (`MG_TLS_BUILTIN`) is a mandatory high-risk review target. Perform a substantial security analysis of all security-relevant built-in TLS code, including parsing, cryptographic processing, authentication and certificate validation, length and buffer handling, protocol state, cross-call behavior, and failure paths. + +Trace attacker-controlled TLS peer input through normal client and server execution, including traffic received before peer authentication is complete. Report any credible memory-safety, authentication, confidentiality, integrity, state-corruption, or remotely triggerable availability vulnerability. + +Do not set `review_completed` to `true` unless the built-in TLS implementation has been meaningfully inspected as a whole. + + **C Memory Safety and Length-Handling Vulnerabilities:** - Look for writes to fixed-size stack or heap buffers where the loop bound is derived from attacker-controlled protocol fields, including topic counts, header counts, chunk counts, multipart parts, DNS labels, WebSocket fragments, TCP/IP options, or filesystem path components. - Check all conversions between `size_t`, `int`, `long`, `uint16_t`, `uint32_t`, and signed protocol lengths. Flag integer truncation, wraparound, negative-to-large conversion, or off-by-one behavior that can affect allocation, parsing, copying, or bounds checks.