fix: Honor --external-manifest option on export and inspect paths - #355
Merged
Merged
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #355 +/- ##
==========================================
+ Coverage 76.42% 79.39% +2.97%
==========================================
Files 4 4
Lines 1073 1097 +24
==========================================
+ Hits 820 871 +51
+ Misses 253 226 -27 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
tmathern
approved these changes
Sep 29, 2026
ok-nick
approved these changes
Oct 2, 2026
Collaborator
|
Backport-action backported this pull request in workflow run 37097441106.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes in this pull request
Vulnerability
--external-manifestis documented to override the asset's embedded/remote manifest, but it was honored only on the default read path. Adding--output DIR(and--certs,--tree,--ingredient,info) silently fell back to the embedded store, so exported reports could validate the very manifest the operator overrode.Fix
Route the reader-based paths (
--outputreport,--certs,--tree) through a sharedread_assethelper that applies the external manifest when set. The ingredient andinfopaths build from the embedded manifest and cannot substitute an external one, so they now reject--external-manifestwith a clear error instead of ignoring it. Behavior is unchanged when the flag is absent.Backward compatibility
Changes are gated on
--external-manifestbeing present, so any invocation without the flag runs the same code as before — no change to--help, arg parsing, defaults, or the SDK/Cargo surface. The only behavior changes affect combinations that were previously silently wrong:--external-manifest--external-manifest(default read)--external-manifest --output DIRInvalid); success exit code unchanged--external-manifest --certs--external-manifest --tree--external-manifest --ingredient(folder or plain)0, misleading output0--external-manifest --info0, misleading output0The ingredient/info combinations never honored the override, so the previous success was misleading rather than correct.
Tests added
Integration tests covering every modified combination: default read and
--outputreport areInvalidfor a mismatched sidecar andValidfor a matching one;--treereflects the sidecar's manifest;--certsyields a cert chain only from the sidecar (the bare asset has none);--ingredient(folder and plain) and--infoerror out.Checklist
TO DOitems (or similar) have been entered as GitHub issues and the link to that issue has been included in a comment.