Clear the code scanning alerts in the workflows and the Dependabot config - #87
Merged
Merged
Conversation
zizmor's artipacked audit flagged 13 actions/checkout steps that keep the GITHUB_TOKEN in the repository's .git/config for the rest of the job, where every later step can read it, and an artifact that uploads the checkout would carry it. No job here pushes with git: the release attaches to a tag that is already pushed (skipTag), and the draft release, the dependency graph and the CodeQL results go through the API with their own tokens. Every checkout now sets persist-credentials: false, as the one in zizmor.yml already did.
sha-pinning-check.yml and update-pr-branch.yml ran with the default GITHUB_TOKEN permissions, which zizmor (excessive-permissions) and CodeQL (actions/missing-workflow-permissions) both flagged. The pin check only checks the repository out and reads its workflow files, so it gets contents: read. update-pr-branch reads and updates the pull requests with BOT_PAT, the only token the action reads, so the workflow's own token gets no permissions at all.
The Dependabot auto-merge job ran when github.actor was dependabot[bot]. zizmor (bot-conditions) flags that as spoofable: the actor is whoever caused the event, so a run Dependabot triggers on a pull request someone else opened passes the check, and the job then approves the pull request and enables auto-merge. The job now checks github.event.pull_request.user.login, the author of the pull request, which is the condition GitHub's own documentation for Dependabot auto-merge uses. dependabot/fetch-metadata still checks the author and that the commits are Dependabot's before anything is approved.
The JDK jobs in ci.yml put ${{ steps.test-jdk.outputs.path }}, the
path actions/setup-java reports, straight into the build's shell
script. zizmor (template-injection) flags that: a template expansion is
pasted into the script before the shell runs it, so a value with shell
syntax in it would run as code. The path now reaches the shell as
TEST_JDK in the step's environment and is quoted there. The matrix
values stay inline: they are fixed in the workflow itself, and zizmor
does not flag them.
The CodeQL workflow pins github/codeql-action to 1c5b6756, commented as v4. v4 is a moving tag and now points to 2892aa5e (v4.38.2), so zizmor (ref-version-mismatch) reports that the comment does not match the pin. 1c5b6756 is v4.38.1, and the comments now say so. The pinned commit stays the same; Dependabot updates it, and the comment with it.
zizmor (dependabot-cooldown) flagged both update entries in dependabot.yml: without a cooldown, Dependabot waits only its implicit three days before it proposes a new version of an action or a Gradle dependency. A compromised or broken release is usually pulled within days, and the auto-merge workflow approves minor and patch updates on its own, so both entries now wait seven days. The cooldown applies to version updates only; security updates are not delayed.
abashev
enabled auto-merge (squash)
September 27, 2026 19:10
abashev
disabled auto-merge
September 27, 2026 19:38
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Before this PR
The repository's code scanning page listed 23 open alerts, all in
.github: 21 from zizmor and 2 from CodeQL's Actions queries. None are in the Java code.After this PR
==COMMIT_MSG==
The workflows and the Dependabot configuration no longer trip the code scanning audits:
actions/checkoutsetspersist-credentials: false, so theGITHUB_TOKENno longer stays in.git/configfor the rest of the job (zizmorartipacked, 13 alerts);sha-pinning-check.ymlruns withcontents: read, andupdate-pr-branch.ymlgives the workflow's own token no permissions, because the action works withBOT_PATalone (zizmorexcessive-permissions, 2; CodeQLactions/missing-workflow-permissions, 2);github.event.pull_request.user.login, instead ofgithub.actor(zizmorbot-conditions, 1);ci.ymlhand the test JDK's path to the shell as a variable instead of pasting a step output into the script (zizmortemplate-injection, 1);github/codeql-actionpin is commented with the release it points to,v4.38.1, instead of the movingv4(zizmorref-version-mismatch, 2);dependabot-cooldown, 2).==COMMIT_MSG==
One commit per rule. What each change relies on was checked first: no job pushes with git (JReleaser attaches the draft release to the existing tag,
skipTag = true);adRise/update-pr-branchreads only itstokeninput, in its bundleddest/index.jsat the pinned commit;1c5b6756isv4.38.1(git ls-remote, peeled tags); GitHub documents the pull request author check for Dependabot auto-merge, anddependabot/fetch-metadatastill verifies the author and the commits before anything is approved.Every workflow parses (
act --list, PyYAML). zizmor is not installed locally, so this PR's zizmor and CodeQL runs are the check that nothing is left; the alerts themselves close once the fixes are on main.Possible downsides?