Skip to content

ci: finish checkout-credential and action-pin hardening across all workflows #3313

Description

@Xore

What

#3282 set persist-credentials: false and SHA-pinned actions for security.yml and two frontend jobs in quality.yml. The rest of the tree was left as is. Current main:

workflow checkouts persist-credentials: false tag-pinned uses:
quality.yml 17 2 29
deploy.yml 2 0 2
containers.yml 1 0 6
pages.yml 1 0 4
dependency-review.yml 1 0 2
image-security-scan.yml, dependabot-auto-merge.yml, the five *-watch.yml 1 each 0 1+ each

30 of 33 checkouts leave the GITHUB_TOKEN in .git/config on the runner. Most jobs run on the shared self-hosted honeypot-ci runner, and deploy.yml there also holds the deploy SSH material.

Proposal

  • persist-credentials: false on every checkout that does not push. Audit for git push first; none is expected outside Dependabot tooling.
  • Pin every third-party uses: to a full SHA with a # vX.Y.Z comment. Dependabot's github-actions ecosystem already bumps SHA pins.
  • Default workflow permissions: {} with job-scoped grants where a workflow currently grants write at top level (dependabot-auto-merge.yml contents: write, the watch workflows' issues: write).
  • Enforce it with the workflow-lint gate (ci: run actionlint + zizmor as a fail-closed workflow gate (.github/actionlint.yaml exists but nothing runs it) #3314) so it cannot regress.

Sources

Found by the #3194 OmniRoute ops/CI deep-check (pinned 18bbb101, APIARY main 3dca4457).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestopsDeployment, runners, observability, host accesssecuritySecurity hardening or a security defect

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions