Skip to content

fix: use least-privilege shared workflows - #57

Closed
VinnyBarton wants to merge 1 commit into
mainfrom
fix/shared-workflow-permissions
Closed

VinnyBarton wants to merge 1 commit into
mainfrom
fix/shared-workflow-permissions

Conversation

@VinnyBarton

Copy link
Copy Markdown
Collaborator

Summary

  • pin every shared workflow call to the permission-boundary correction in supply-chain-workflows#12
  • preserve full immutable commit pins
  • validate all sbom-validator workflow files after the update

Root cause

The shared ReARM, source SBOM, and Interlynk workflows declared permissions: read-all at the reusable-workflow boundary. The sbom-validator callers grant only their required scopes. GitHub does not permit a called workflow to request permissions absent from the caller, so runs 37677769537 and 37677769568 were rejected before jobs were created.

The shared fix replaces read-all with exact scopes and adds a policy check preventing this regression.

Dependency

Merge shiftleftcyber/supply-chain-workflows#12 first. This PR is pinned to that PR's full commit SHA, which remains immutable after merge.

Verification

  • Actionlint v1.7.7 and ShellCheck passed across every repository workflow
  • git diff --check passed
  • the referenced shared-workflow commit passed local policy, ShellCheck, Actionlint, and Zizmor checks

Configured CI checks must pass before merge.

@VinnyBarton

Copy link
Copy Markdown
Collaborator Author

Superseded by #58, which moves every shared-workflow reference to the validated v1 compatibility channel. #58 has a fully passing CI suite.

@VinnyBarton VinnyBarton closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant