Skip to content

fix: restrict e2e workflow token and validate dispatch SHAs - #69

Merged
kitfoster merged 1 commit into
mainfrom
fix/e2e-dispatch-least-privilege
Sep 17, 2026
Merged

kitfoster merged 1 commit into
mainfrom
fix/e2e-dispatch-least-privilege

Conversation

@tim123abc

Copy link
Copy Markdown
Contributor

Summary

  • Pin e2e GitHub Actions jobs to contents: read + statuses: write so repository_dispatch from an authorized fork preview cannot run with contents: write.
  • Validate client_payload.git.sha against first-party branches/tags before checkout, drop secrets: inherit, and disable persisted checkout credentials.
  • Follow-up still required after merge: rotate DEPLOYMENT_PROTECTION_BYPASS and FLAGS_SECRET in GitHub and Vercel.

Test plan

  • Merge to main (dispatch workflows only pick up this change from the default branch)
  • Confirm a same-repo preview or workflow_dispatch still runs e2e and posts commit statuses
  • Confirm a fork preview dispatch fails at "Validate deployment SHA" and does not check out untrusted code
  • Rotate DEPLOYMENT_PROTECTION_BYPASS and FLAGS_SECRET

…ccess

Authorized Vercel preview dispatches could check out a fork commit and execute it with the default contents: write token and repository secrets.
@vercel

vercel Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Your Vercel team microfrontends-vtest314 is not permitted to deploy from this git repository. Contact an administrator to add github organization vercel as a Protected Git Scope in microfrontends-vtest314 on Vercel. Once added, commit again to see your changes.

Learn more: https://vercel.com/docs/security/protected-git-scopes

@tim123abc
tim123abc enabled auto-merge (squash) September 16, 2026 17:33
@kitfoster
kitfoster disabled auto-merge September 17, 2026 08:39
@kitfoster
kitfoster merged commit 69ededb into main Sep 17, 2026
5 of 17 checks passed
@kitfoster
kitfoster deleted the fix/e2e-dispatch-least-privilege branch September 17, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants