Skip to content

fork companion CircleCI clones upstream and never tests security branches #603

Description

@BitHighlander

Summary

The companion python-keepkey CircleCI job does not test fork pull-request branches. Its first step constructs this clone unconditionally:

git clone --depth 1 -b "$CIRCLE_BRANCH" https://github.com/keepkey/python-keepkey.git .pykk

Fork-only branches such as BitHighlander/python-keepkey:fix/alpha-audit-followups do not exist in keepkey/python-keepkey, so the required ci/circleci: emulator-build-test context fails before checkout or testing.

CircleCI build 358 at Python head f19a5f6a confirms exit 128 in 174 ms at Clone python-keepkey (current branch). The job then never exercises the emulator, screenshot gate, storage fixtures, or signing tests.

Security/CI impact

  • The fork tracker reports a required red check unrelated to the patch.
  • More importantly, the legacy job cannot provide any independent evidence for fork-only security remediations.
  • Its firmware checkout also follows an environment-provided master branch rather than the exact companion firmware revision, so even a successful checkout can test a different signing implementation than the Python regression targets.

Required remediation

  • Clone ${CIRCLE_PROJECT_USERNAME}/${CIRCLE_PROJECT_REPONAME} over HTTPS at the exact $CIRCLE_BRANCH, rather than hard-coding the upstream owner.
  • Pin the firmware checkout to the exact companion revision under review, matching the GitHub Actions integration lane.
  • Confirm CircleCI reaches the emulator suite and reports its own status file rather than failing at clone time.

Evidence: https://circleci.com/gh/BitHighlander/python-keepkey/358

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions