Files
learningcircuit--local-deep…/.github/FUZZING.md
T
wehub-resource-sync 7a0da7932b
OSV-Scanner (Scheduled) / scan-scheduled (push) Failing after 0s
Create Release / test-gate (push) Has been cancelled
Create Release / release-gate (push) Has been cancelled
Create Release / ci-gate (push) Has been cancelled
Create Release / version-check (push) Has been cancelled
Create Release / e2e-test-gate (push) Has been cancelled
Create Release / responsive-test-gate (push) Has been cancelled
Create Release / compat-test-gate (push) Has been cancelled
Create Release / compose-integration-gate (push) Has been cancelled
Create Release / vulture-gate (push) Has been cancelled
Create Release / build (push) Has been cancelled
Create Release / provenance (push) Has been cancelled
Create Release / prerelease-docker (push) Has been cancelled
Create Release / publish-docker (push) Has been cancelled
Create Release / create-release (push) Has been cancelled
Create Release / cleanup-changelog (push) Has been cancelled
Create Release / trigger-pypi (push) Has been cancelled
Create Release / monitor-pypi (push) Has been cancelled
Create Release / Clean up orphan prerelease tags and signatures (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-form] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-metrics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-workflow] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-core] (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [history-news] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [library] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [link-analytics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-core] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-lifecycle] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [error-benchmark] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) (push) Has been cancelled
Docker Tests (Consolidated) / Accessibility Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Unit Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Example Tests (push) Has been cancelled
Docker Tests (Consolidated) / Production Image Smoke Test (push) Has been cancelled
Docker Tests (Consolidated) / Infrastructure Tests (push) Has been cancelled
OSSF Scorecard / OSSF Security Scorecard Analysis (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [mobile] (push) Has been cancelled
Backwards Compatibility / Verify Encryption Constants (push) Has been cancelled
Backwards Compatibility / PyPI Version Compatibility (push) Has been cancelled
Backwards Compatibility / Database Migration Tests (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Docker Tests (Consolidated) / detect-changes (push) Has been cancelled
Docker Tests (Consolidated) / Build Test Image (push) Has been cancelled
Docker Tests (Consolidated) / All Pytest Tests + Coverage (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [accessibility] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [api-crud] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-login] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-register] (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 13:08:55 +08:00

69 lines
2.2 KiB
Markdown

# Fuzzing Strategy
This document explains our fuzzing approach and addresses OSSF Scorecard's
Fuzzing check.
## Current Implementation
This project uses **Hypothesis** for property-based fuzz testing:
- **Workflow**: `.github/workflows/fuzz.yml`
- **Tests**: `tests/fuzz/test_fuzz_security.py`, `tests/fuzz/test_fuzz_utilities.py`
- **Schedule**: Weekly on Sunday + on changes to security/utilities code
### What We Test
Our fuzz tests cover:
- Input validation edge cases
- Security-sensitive string handling
- API boundary testing
- File path validation
- URL parsing and sanitization
### Test Configuration
```yaml
# Regular CI runs
--hypothesis-seed=0 # Reproducible tests
# Extended scheduled runs
HYPOTHESIS_PROFILE=extended # More examples, deeper exploration
```
## Why Not OSS-Fuzz?
OSSF Scorecard's Fuzzing check looks for integration with:
- [OSS-Fuzz](https://github.com/google/oss-fuzz) - Google's continuous fuzzing
- [ClusterFuzzLite](https://google.github.io/clusterfuzzlite/) - Lightweight alternative
- [OneFuzz](https://github.com/microsoft/onefuzz) - Microsoft's fuzzing platform
**These are not appropriate for this project because:**
1. **OSS-Fuzz targets native code** - Designed for C/C++ vulnerabilities using
libFuzzer/AFL++. This project is primarily Python.
2. **Hypothesis is the Python equivalent** - Property-based testing with
automatic example generation provides equivalent security value.
3. **No native code attack surface** - Our security-sensitive code is Python,
where Hypothesis testing is the standard approach.
## OSSF Scorecard Note
Scorecard's "Fuzzing" check does not recognize Hypothesis-based testing.
This is a known limitation of the check. Our fuzzing implementation provides
equivalent security value for Python codebases.
## Future Considerations
If the project adds significant native code dependencies (C extensions, FFI),
we would consider:
- ClusterFuzzLite integration for continuous fuzzing
- Native fuzz targets for critical C code paths
## References
- [Hypothesis Documentation](https://hypothesis.readthedocs.io/)
- [OSSF Scorecard Fuzzing Check](https://github.com/ossf/scorecard/blob/main/docs/checks.md#fuzzing)
- [Property-Based Testing in Python](https://hypothesis.works/)