Skip to content

Clear the code scanning alerts in the workflows and the Dependabot config - #87

Merged
abashev merged 6 commits into
mainfrom
code-scanning-alerts
Sep 27, 2026
Merged

abashev merged 6 commits into
mainfrom
code-scanning-alerts

Conversation

@abashev

@abashev abashev commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

Before this PR

The repository's code scanning page listed 23 open alerts, all in .github: 21 from zizmor and 2 from CodeQL's Actions queries. None are in the Java code.

After this PR

==COMMIT_MSG==
The workflows and the Dependabot configuration no longer trip the code scanning audits:

  • every actions/checkout sets persist-credentials: false, so the GITHUB_TOKEN no longer stays in .git/config for the rest of the job (zizmor artipacked, 13 alerts);
  • sha-pinning-check.yml runs with contents: read, and update-pr-branch.yml gives the workflow's own token no permissions, because the action works with BOT_PAT alone (zizmor excessive-permissions, 2; CodeQL actions/missing-workflow-permissions, 2);
  • the Dependabot auto-merge job checks who opened the pull request, github.event.pull_request.user.login, instead of github.actor (zizmor bot-conditions, 1);
  • the JDK jobs in ci.yml hand the test JDK's path to the shell as a variable instead of pasting a step output into the script (zizmor template-injection, 1);
  • the github/codeql-action pin is commented with the release it points to, v4.38.1, instead of the moving v4 (zizmor ref-version-mismatch, 2);
  • Dependabot proposes a new version only once it is a week old (zizmor dependabot-cooldown, 2).
    ==COMMIT_MSG==

One commit per rule. What each change relies on was checked first: no job pushes with git (JReleaser attaches the draft release to the existing tag, skipTag = true); adRise/update-pr-branch reads only its token input, in its bundled dest/index.js at the pinned commit; 1c5b6756 is v4.38.1 (git ls-remote, peeled tags); GitHub documents the pull request author check for Dependabot auto-merge, and dependabot/fetch-metadata still verifies the author and the commits before anything is approved.

Every workflow parses (act --list, PyYAML). zizmor is not installed locally, so this PR's zizmor and CodeQL runs are the check that nothing is left; the alerts themselves close once the fixes are on main.

Possible downsides?

  • Version updates from Dependabot now arrive a week after a release rather than three days. Security updates are not delayed: the cooldown applies to version updates only.
  • A step that pushes with git in the future needs credentials of its own, since no checkout keeps them any more. No job does that today.

zizmor's artipacked audit flagged 13 actions/checkout steps that keep
the GITHUB_TOKEN in the repository's .git/config for the rest of the
job, where every later step can read it, and an artifact that uploads
the checkout would carry it. No job here pushes with git: the release
attaches to a tag that is already pushed (skipTag), and the draft
release, the dependency graph and the CodeQL results go through the
API with their own tokens. Every checkout now sets
persist-credentials: false, as the one in zizmor.yml already did.
sha-pinning-check.yml and update-pr-branch.yml ran with the default
GITHUB_TOKEN permissions, which zizmor (excessive-permissions) and
CodeQL (actions/missing-workflow-permissions) both flagged. The pin
check only checks the repository out and reads its workflow files, so
it gets contents: read. update-pr-branch reads and updates the pull
requests with BOT_PAT, the only token the action reads, so the
workflow's own token gets no permissions at all.
The Dependabot auto-merge job ran when github.actor was
dependabot[bot]. zizmor (bot-conditions) flags that as spoofable: the
actor is whoever caused the event, so a run Dependabot triggers on a
pull request someone else opened passes the check, and the job then
approves the pull request and enables auto-merge.

The job now checks github.event.pull_request.user.login, the author of
the pull request, which is the condition GitHub's own documentation
for Dependabot auto-merge uses. dependabot/fetch-metadata still checks
the author and that the commits are Dependabot's before anything is
approved.
The JDK jobs in ci.yml put ${{ steps.test-jdk.outputs.path }}, the
path actions/setup-java reports, straight into the build's shell
script. zizmor (template-injection) flags that: a template expansion is
pasted into the script before the shell runs it, so a value with shell
syntax in it would run as code. The path now reaches the shell as
TEST_JDK in the step's environment and is quoted there. The matrix
values stay inline: they are fixed in the workflow itself, and zizmor
does not flag them.
The CodeQL workflow pins github/codeql-action to 1c5b6756, commented
as v4. v4 is a moving tag and now points to 2892aa5e (v4.38.2), so
zizmor (ref-version-mismatch) reports that the comment does not match
the pin. 1c5b6756 is v4.38.1, and the comments now say so. The pinned
commit stays the same; Dependabot updates it, and the comment with it.
zizmor (dependabot-cooldown) flagged both update entries in
dependabot.yml: without a cooldown, Dependabot waits only its implicit
three days before it proposes a new version of an action or a Gradle
dependency. A compromised or broken release is usually pulled within
days, and the auto-merge workflow approves minor and patch updates on
its own, so both entries now wait seven days. The cooldown applies to
version updates only; security updates are not delayed.
@abashev
abashev enabled auto-merge (squash) September 27, 2026 19:10
@abashev
abashev disabled auto-merge September 27, 2026 19:38
@abashev
abashev merged commit 9610f9f into main Sep 27, 2026
16 checks passed
@abashev
abashev deleted the code-scanning-alerts branch September 27, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant