chore(guard): sync vendored public-repo-guard to canonical - #41
chore(guard): sync vendored public-repo-guard to canonical#41wave-av-release-bot[bot] wants to merge 1 commit into
Conversation
|
PR author is in the excluded authors list. |
ApprovabilityVerdict: Needs human review Unable to check for correctness in b3d2ef6. This PR updates a workflow file owned by wave-av/streaming-team, but the author (wave-av-release-bot) is not a designated owner. While the change is a straightforward security improvement (version bump + persist-credentials: false), the designated code owners should review changes to their files. You can customize Macroscope's approvability policy. Learn more. |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| with: | ||
| # Checkout defaults to persisting the job token for later steps: since v6 it | ||
| # lives in a file under $RUNNER_TEMP referenced from .git/config, no longer in | ||
| # .git/config itself. It is still a live credential in the job, and this job | ||
| # downloads a third-party binary (gitleaks, below) and runs it over the whole | ||
| # tree. Nothing here pushes -- the scan is `--no-git` over the working tree -- | ||
| # so no step needs authenticated Git; drop it. (zizmor: artipacked) | ||
| persist-credentials: false |
There was a problem hiding this comment.
🔍 Checkout pin now inconsistent with the rest of the workflows (v4 elsewhere)
This bumps only public-repo-guard.yml to checkout v7 (.github/workflows/public-repo-guard.yml:45), while .github/workflows/_checks.yml:23,54,114 remain pinned to v4.3.1 and still persist credentials by default. If the intent is the zizmor artipacked hardening, the same persist-credentials: false treatment likely belongs on the other checkout steps too (they run tests/builds, none of which appear to need an authenticated Git remote). Worth confirming whether the other workflows were intentionally left alone.
Was this helpful? React with 👍 or 👎 to provide feedback.
Syncs the vendored
public-repo-guardtrio to the canonical source inwave-foundation/scaffolder/public-repo-guard.internal-ipleak rule (Tailscale-CGNAT100.64.0.0/10), lockstep with the pre-publish mirror gateEach changed file is byte-for-byte identical to canonical (verified by git blob SHA). The repo's own
Secrets + content policygate re-scans this PR.🤖 Generated with Claude Code
Note
Update
public-repo-guardworkflow to useactions/checkoutv7 without persisted credentialsSyncs public-repo-guard.yml to the canonical version. Upgrades
actions/checkoutfrom v5.0.1 to v7.0.0 and setspersist-credentials: falseso theGITHUB_TOKENis no longer stored in the repository's Git config after checkout.Macroscope summarized b3d2ef6.
Summary by cubic
Syncs vendored
public-repo-guardwith the canonical repo to align leak rules and workflow hardening. Adds theinternal-iprule for Tailscale CGNAT (100.64.0.0/10), bumpsactions/checkoutto v7, and disablespersist-credentialsduring scans.Written for commit b3d2ef6. Summary will update on new commits.