ci: apply focused OmniRoute CI hardening for #3194 - #3282
Merged
Merged
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
This was referenced Sep 26, 2026
Xore
added a commit
that referenced
this pull request
Sep 27, 2026
…rkflows (#3313) (#3388) #3282 set persist-credentials: false and SHA-pinned actions for security.yml and two frontend jobs in quality.yml. The rest of the tree was left as is: 30 of 33 checkouts left the GITHUB_TOKEN in .git/config on the runner, most of them on the shared self-hosted honeypot-ci executor that deploy.yml also holds the deploy SSH material on, and 80-odd third-party `uses:` were still tag-pinned. Finishes all three proposals across all 19 workflows. persist-credentials: false on every checkout. Audited for `git push` first: none exists outside Dependabot tooling, so no checkout needs the token left on disk. 35 checkouts, 0 without it. Full-SHA pins with a `# vX.Y.Z` comment on every third-party `uses:` (52 references). SHAs resolved with `git ls-remote --tags`, not copied from a release page. Dependabot's github-actions ecosystem already covers `/` with no ignore rules, so it keeps bumping these. Two pins that were already SHAs gained a version comment, and quality.yml's two setup-node pins said `# v7` where the tag is v7.0.0. permissions: {} at workflow level on the 13 workflows that granted a write scope there, with the grant moved to the job that spends it. actions: write existed only so the ci-target job could call the reusable ci-router.yml and dispatch the ci-heartbeat canary, so it stays on ci-target and no longer reaches the other 24 jobs in quality.yml; packages: write is now on containers.yml's build job alone, and security-events: write on security.yml's analyze job alone. Verified job by job that every job's effective envelope is equal or narrower than before: no job gained a scope, and the dropped ones each had a single consumer that keeps its grant. deploy.yml, diagnostics.yml, vps-start-blackhole.yml and ci-router.yml grant no write scope at the workflow level and are left alone. Enforced rather than asserted: #3314's zizmor step listed unpinned-uses, excessive-permissions and artipacked as advisory "until #3313 lands". They are dropped from ADVISORY, so a regression in any of them is now a blocking finding. The two rules left advisory are documented inline with why: the five `uses: ./.github/workflows/ci-router.yml` calls (zizmor wants the owner/repo/path@ref form; the local-path form is GitHub's own first-party syntax and is what lets the shared router change without a second SHA to bump), and main-health-watch.yml's workflow_run (it runs the default branch's copy of the script and reads no event payload -- every value it reports comes from a main-scoped API read, and changing the trigger would blind the #3324 alarm that exists to catch runs nobody started). zizmor on the tree: unpinned-uses 51 -> 0, excessive-permissions 7 -> 0, artipacked 27 -> 0, with the gate now passing. actionlint 1.7.7 clean, all 19 workflows parse, and tests/docs (444) plus scripts/tests (193 of 195; the two compose-drift-watch_sweep privileged-fallback failures are pre-existing on the base commit) pass. Co-authored-by: Dev Operator <dev@localhost>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is the focused CI/ops slice of issue #3194. It applies only the verified, bounded findings from the recorded research; it does not claim that the 55-file OmniRoute campaign is complete.
Scope: CI/ops only. No product code, deployment configuration, production changes, secrets, runner registration, or
deploy.ymlchanges are included.Adopt
.github/dependabot.yml.github/dependabot.ymlCargo.toml/Cargo.lock, using APIARY's weekly minor/patch grouping. This is an APIARY-specific coverage repair inspired by the upstream ecosystem discipline; OmniRoute's reviewed file has no Cargo stanza.file-24/result.json.github/dependabot.yml.github/dependabot.ymlfile-24/result.json.github/workflows/codeql.yml.github/workflows/security.ymlpersist-credentials: falseon checkout.file-45/result.json.github/workflows/codeql.ymldocs/CI-CD.mddocs/ops/directory, so this uses the existing CI/CD runbook.file-45/result.json.github/workflows/api-route-typecheck.yml.github/workflows/quality.ymlcheckoutandsetup-nodereferences and disable persisted checkout credentials in both frontend runner variants.file-50/result.jsonSkip
tsc --noEmitin both frontend Quality variants;api-route-typecheck.ymlwould duplicate coverage and does not match APIARY's Vite/TanStack layout./electronwould not fit.deploy.ymlVerification
Commands and real output from this branch:
Also verified independently with GitHub:
No
402or429occurred during this implementation. The pre-existing untrackedrun.logwas not modified or included. This PR is opened for review and is not merged.