Clear the code scanning alerts in the workflows and the Dependabot config - #10
Merged
Merged
Conversation
zizmor's artipacked audit flagged 6 actions/checkout steps that keep the GITHUB_TOKEN in the repository's .git/config for the rest of the job, where every later step can read it, and an artifact that uploads the checkout would carry it. No job here pushes with git: the draft release attaches to a tag that is already pushed (skipTag), and the Central upload, the draft release, the dependency graph and the CodeQL results go through APIs with their own tokens. Every checkout now sets persist-credentials: false, as the one in zizmor.yml already did.
sha-pinning-check.yml and update-pr-branch.yml ran with the default GITHUB_TOKEN permissions, which zizmor (excessive-permissions) and CodeQL (actions/missing-workflow-permissions) both flagged. The pin check only checks the repository out and reads its workflow files, so it gets contents: read. update-pr-branch reads and updates the pull requests with BOT_PAT, the only token the action reads, so the workflow's own token gets no permissions at all.
The Dependabot auto-merge job ran when github.actor was dependabot[bot]. zizmor (bot-conditions) flags that as spoofable: the actor is whoever caused the event, so a run Dependabot triggers on a pull request someone else opened passes the check, and the job then approves the pull request and enables auto-merge. The job now checks github.event.pull_request.user.login, the author of the pull request, which is the condition GitHub's own documentation for Dependabot auto-merge uses. dependabot/fetch-metadata still checks the author and that the commits are Dependabot's before anything is approved.
The CodeQL workflow pins github/codeql-action to 1c5b6756, commented as v4. v4 is a moving tag and now points to 2892aa5e (v4.38.2), so zizmor (ref-version-mismatch) reports that the comment does not match the pin. 1c5b6756 is v4.38.1, and the comments now say so. The pinned commit stays the same; Dependabot updates it, and the comment with it.
zizmor (dependabot-cooldown) flagged both update entries in dependabot.yml: without a cooldown, Dependabot waits only its implicit three days before it proposes a new version of an action or a Maven dependency. A compromised or broken release is usually pulled within days, and the auto-merge workflow approves minor and patch updates on its own, so both entries now wait seven days. The cooldown applies to version updates only; security updates are not delayed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The repository's code scanning page listed 15 open alerts, all in
.github: 13 from zizmor and 2 fromCodeQL's Actions queries. This clears them, one commit per rule:
actions/checkoutsetspersist-credentials: false, so theGITHUB_TOKENno longer stays in.git/configfor the rest of the job. No job pushes with git: the draft release attaches to the tagthat is already pushed (
skipTag), and everything else goes through APIs with its own token (zizmorartipacked, 6).sha-pinning-check.ymlruns withcontents: read, andupdate-pr-branch.ymlgives the workflow'sown token no permissions, because
adRise/update-pr-branchreads only itstokeninput,BOT_PAT(zizmor
excessive-permissions, 2; CodeQLactions/missing-workflow-permissions, 2).github.event.pull_request.user.login, instead ofgithub.actor, as GitHub's documentation forDependabot auto-merge does;
dependabot/fetch-metadatastill verifies the author and the commitsbefore anything is approved (zizmor
bot-conditions, 1).github/codeql-actionpin is commented with the release it points to,v4.38.1, instead of themoving
v4, which now meansv4.38.2(zizmorref-version-mismatch, 2).instead of after three days; security updates are not delayed (zizmor
dependabot-cooldown, 2).These are the changes of openjavaformat/open-java-format#87, where zizmor already reports no findings on
the pull request. Every workflow parses (
act --list, PyYAML); this pull request's zizmor and CodeQLruns are the check that nothing is left, and the alerts close once it is on main.