Skip to content

Clear the code scanning alerts in the workflows and the Dependabot config - #10

Merged
abashev merged 5 commits into
mainfrom
code-scanning-alerts
Sep 27, 2026
Merged

abashev merged 5 commits into
mainfrom
code-scanning-alerts

Conversation

@abashev

@abashev abashev commented Sep 27, 2026

Copy link
Copy Markdown

The repository's code scanning page listed 15 open alerts, all in .github: 13 from zizmor and 2 from
CodeQL's Actions queries. This clears them, one commit per rule:

  • Every actions/checkout sets persist-credentials: false, so the GITHUB_TOKEN no longer stays in
    .git/config for the rest of the job. No job pushes with git: the draft release attaches to the tag
    that is already pushed (skipTag), and everything else goes through APIs with its own token (zizmor
    artipacked, 6).
  • sha-pinning-check.yml runs with contents: read, and update-pr-branch.yml gives the workflow's
    own token no permissions, because adRise/update-pr-branch reads only its token input, BOT_PAT
    (zizmor excessive-permissions, 2; CodeQL actions/missing-workflow-permissions, 2).
  • The Dependabot auto-merge job checks who opened the pull request,
    github.event.pull_request.user.login, instead of github.actor, as GitHub's documentation for
    Dependabot auto-merge does; dependabot/fetch-metadata still verifies the author and the commits
    before anything is approved (zizmor bot-conditions, 1).
  • The github/codeql-action pin is commented with the release it points to, v4.38.1, instead of the
    moving v4, which now means v4.38.2 (zizmor ref-version-mismatch, 2).
  • Dependabot proposes a new version of an action or a Maven dependency only once it is a week old,
    instead of after three days; security updates are not delayed (zizmor dependabot-cooldown, 2).

These are the changes of openjavaformat/open-java-format#87, where zizmor already reports no findings on
the pull request. Every workflow parses (act --list, PyYAML); this pull request's zizmor and CodeQL
runs are the check that nothing is left, and the alerts close once it is on main.

zizmor's artipacked audit flagged 6 actions/checkout steps that keep
the GITHUB_TOKEN in the repository's .git/config for the rest of the
job, where every later step can read it, and an artifact that uploads
the checkout would carry it. No job here pushes with git: the draft
release attaches to a tag that is already pushed (skipTag), and the
Central upload, the draft release, the dependency graph and the CodeQL
results go through APIs with their own tokens. Every checkout now sets
persist-credentials: false, as the one in zizmor.yml already did.
sha-pinning-check.yml and update-pr-branch.yml ran with the default
GITHUB_TOKEN permissions, which zizmor (excessive-permissions) and
CodeQL (actions/missing-workflow-permissions) both flagged. The pin
check only checks the repository out and reads its workflow files, so
it gets contents: read. update-pr-branch reads and updates the pull
requests with BOT_PAT, the only token the action reads, so the
workflow's own token gets no permissions at all.
The Dependabot auto-merge job ran when github.actor was
dependabot[bot]. zizmor (bot-conditions) flags that as spoofable: the
actor is whoever caused the event, so a run Dependabot triggers on a
pull request someone else opened passes the check, and the job then
approves the pull request and enables auto-merge.

The job now checks github.event.pull_request.user.login, the author of
the pull request, which is the condition GitHub's own documentation
for Dependabot auto-merge uses. dependabot/fetch-metadata still checks
the author and that the commits are Dependabot's before anything is
approved.
The CodeQL workflow pins github/codeql-action to 1c5b6756, commented
as v4. v4 is a moving tag and now points to 2892aa5e (v4.38.2), so
zizmor (ref-version-mismatch) reports that the comment does not match
the pin. 1c5b6756 is v4.38.1, and the comments now say so. The pinned
commit stays the same; Dependabot updates it, and the comment with it.
zizmor (dependabot-cooldown) flagged both update entries in
dependabot.yml: without a cooldown, Dependabot waits only its implicit
three days before it proposes a new version of an action or a Maven
dependency. A compromised or broken release is usually pulled within
days, and the auto-merge workflow approves minor and patch updates on
its own, so both entries now wait seven days. The cooldown applies to
version updates only; security updates are not delayed.
@abashev
abashev merged commit b17c44a into main Sep 27, 2026
8 checks passed
@abashev
abashev deleted the code-scanning-alerts branch September 27, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant