場所間を利用してCodex Security-Scanを用いてフルスキャンしてみた。
Versionは Codex-Security CLI 0.1.1
ModelはGPT-5.6-Sol High、時間は約40分。
The scan reviewed the canonical include paths and exclusions listed below.
- Scan mode: repository
- Target kind: git_worktree
- Target ID: target_sha256_0ad2eeaf6bc2d71f7eff4b296604ce0c0315bb552b093dc16368f97c949844b0
- Revision: 7e27af0e756666a67aa7901df74c30ac3786d1bc
- Snapshot digest: codex-security-snapshot/v1:sha256:d749f81681dedb2d0e9504bc9222ae11328b31a2995b214a6a862a3c8aae2abf
- Inventory strategy: repository
- Included paths: .
- Excluded paths: none
- Runtime or test status: not recorded
- Scan context: Whole-repository standard scan. All 309 in-scope files were reviewed. Fifteen candidates were validated; six received attack-path analysis; zero remained reportable.
| Field | Value |
|---|---|
| Reportable findings | 0 |
| Severity mix | none |
| Confidence mix | none |
| Coverage | complete |
| Validation mode | not recorded |
Canonical artifacts: scan-manifest.json, findings.json, and coverage.json. This report is a deterministic projection of those files.
Public read-only React and Vite static site on Cloudflare Pages with a static JSON API and privileged GitHub Actions that ingest fixed external data sources and publish generated content. The principal boundaries are browser-to-static-origin, generated data-to-rendering, external sources-to-generators, and write-enabled automation-to-repository publication.
- Integrity and availability of the public site, routes, PWA, and static JSON API
- Accuracy, provenance, freshness, and schema compatibility of published sumo data
- Integrity of the main branch, automated update branches, and deployment output
- GitHub Actions credentials, optional personal access token, and Discord webhook secret
- User trust in official data, images, links, and third-party browser content
- Arbitrary browser requests to the Cloudflare Pages static origin
- Generated repository data to React text, anchor, and image sinks
- Fixed external sumo and news sources to privileged generators
- GitHub Actions jobs to repository write and publication authority
- Pull-request code, npm packages, GitHub Actions, and browser scripts to trusted execution contexts
- Cloudflare deployment and service-worker caches to visitor clients
- Internet users can control paths, route parameters, URL fragments, browser headers, and normal UI interactions
- A compromised upstream can influence externally fetched HTML, JSON, URLs, and generated public content
- Dependency or GitHub Action publishers can influence third-party code executed during builds and workflows
- Maintainers and trusted automation operators control repository source, workflow dispatches, secrets, and deployment settings
- Keep public requests read-only and prevent access to repository writes, workflow state, secrets, or deployment authority
- Render generated values only as data and constrain browser navigation and resource URLs to intended schemes and origins
- Prevent external content from escaping generated files, altering executable source, or influencing shell commands
- Constrain automation writes to documented paths and validate generated content before publication
- Keep credentials out of generated files, logs, artifacts, browser bundles, and attacker-controlled requests
- Preserve honest routing, API responses, cache recovery, and public data compatibility
- The deployed application has no accounts, authenticated sessions, private user dataset, database, or browser-to-origin write API
- Cloudflare Pages, GitHub, npm, Google script hosting, and fixed upstream HTTPS endpoints provide their documented platform isolation and transport security
- Platform-wide compromise without a repository-controlled mitigation is out of scope, while repository-represented misconfiguration remains in scope
- Local manually invoked utilities are developer surfaces unless a documented automated release path invokes them
No reportable findings survived the canonical discovery, validation, and reportability gates.
| Surface | Risk Area | Outcome | Notes |
|---|---|---|---|
| Browser application and production runtime | Browser trust boundaries, routes, generated data, external resources, PWA, and Cloudflare delivery | Rejected | Two candidates were validated; the malformed-fragment crash was suppressed and the production localhost script was rejected after attack-path analysis. Evidence: artifacts/03_coverage/runtime_receipt.md |
| Automated generators and repository publication workflows | External data ingestion, validation, secrets, workflow permissions, direct pushes, and action supply chain | Rejected | Automation candidates were reproduced and traced, then rejected or suppressed because the remaining paths required trusted upstream, trusted publisher, or maintainer compromise without a lower-privileged in-scope entry path. Evidence: artifacts/03_coverage/automation_docs_receipt.md |
| Static API data and public assets | Static JSON integrity, unsafe URLs, active content, media parsing, and content-type behavior | Rejected | All structured and binary assets were reviewed. The JPEG-in-PNG-name candidate was suppressed after browser and delivery validation showed no active-content impact. Evidence: artifacts/03_coverage/static_assets_receipt.md |
| npm dependency advisories | Known vulnerabilities in build, development, routing, testing, and Cloudflare tooling dependencies | Not applicable | Five normalized advisory groups were checked against configured and reachable features; none produced an applicable product attack path at this revision. Evidence: artifacts/02_discovery/validation_artifacts/dependency-audit/npm-audit.json |
| Repository-wide inventory and review accounting | Coverage completeness and deferred-work accounting | No issue found | All 309 in-scope files were assigned and reviewed; no file, surface, candidate, or question was deferred. Evidence: artifacts/03_coverage/reviewed_surfaces.md, artifacts/03_coverage/repository_coverage_ledger.md |