You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#3282 set persist-credentials: false and SHA-pinned actions for security.yml and two frontend jobs in quality.yml. The rest of the tree was left as is. Current main:
workflow
checkouts
persist-credentials: false
tag-pinned uses:
quality.yml
17
2
29
deploy.yml
2
0
2
containers.yml
1
0
6
pages.yml
1
0
4
dependency-review.yml
1
0
2
image-security-scan.yml, dependabot-auto-merge.yml, the five *-watch.yml
1 each
0
1+ each
30 of 33 checkouts leave the GITHUB_TOKEN in .git/config on the runner. Most jobs run on the shared self-hosted honeypot-ci runner, and deploy.yml there also holds the deploy SSH material.
Proposal
persist-credentials: false on every checkout that does not push. Audit for git push first; none is expected outside Dependabot tooling.
Pin every third-party uses: to a full SHA with a # vX.Y.Z comment. Dependabot's github-actions ecosystem already bumps SHA pins.
Default workflow permissions: {} with job-scoped grants where a workflow currently grants write at top level (dependabot-auto-merge.ymlcontents: write, the watch workflows' issues: write).
What
#3282 set
persist-credentials: falseand SHA-pinned actions forsecurity.ymland two frontend jobs inquality.yml. The rest of the tree was left as is. Currentmain:persist-credentials: falseuses:*-watch.yml30 of 33 checkouts leave the
GITHUB_TOKENin.git/configon the runner. Most jobs run on the shared self-hostedhoneypot-cirunner, anddeploy.ymlthere also holds the deploy SSH material.Proposal
persist-credentials: falseon every checkout that does not push. Audit forgit pushfirst; none is expected outside Dependabot tooling.uses:to a full SHA with a# vX.Y.Zcomment. Dependabot'sgithub-actionsecosystem already bumps SHA pins.permissions: {}with job-scoped grants where a workflow currently grants write at top level (dependabot-auto-merge.ymlcontents: write, the watch workflows'issues: write).Sources
.github/workflows/codeql.yml.github/workflows/dast-smoke.yml.github/workflows/semgrep.yml.github/workflows/scorecard.yml.github/workflows/claude.yml.github/workflows/electron-release.yml.github/workflows/npm-publish.yml.github/workflows/docker-publish.ymlFound by the #3194 OmniRoute ops/CI deep-check (pinned
18bbb101, APIARYmain3dca4457).