chore(guard): sync vendored public-repo-guard to canonical - #60
chore(guard): sync vendored public-repo-guard to canonical#60wave-av-release-bot[bot] wants to merge 1 commit into
Conversation
|
PR author is in the excluded authors list. |
ApprovabilityVerdict: Needs human review Unable to check for correctness in a81a4bd. This PR updates the checkout action version and adds security hardening ( You can customize Macroscope's approvability policy. Learn more. |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| with: | ||
| # Checkout defaults to persisting the job token for later steps: since v6 it | ||
| # lives in a file under $RUNNER_TEMP referenced from .git/config, no longer in | ||
| # .git/config itself. It is still a live credential in the job, and this job | ||
| # downloads a third-party binary (gitleaks, below) and runs it over the whole | ||
| # tree. Nothing here pushes -- the scan is `--no-git` over the working tree -- | ||
| # so no step needs authenticated Git; drop it. (zizmor: artipacked) | ||
| persist-credentials: false |
There was a problem hiding this comment.
🔍 Checkout action versions now diverge across workflows
This workflow moves to actions/checkout@9c091bb… (v7.0.0) while the rest of the repo pins other versions: v6.0.3 in .github/workflows/lint.yml:16 and .github/workflows/release.yml:41,77,131, and v4.3.1 in .github/workflows/_checks.yml:23,54,114. Also, persist-credentials: false is only applied here — the other workflows still persist the job token, so the artipacked hardening the comment describes is only partially rolled out. Worth confirming whether the intent was to standardize all workflows.
Was this helpful? React with 👍 or 👎 to provide feedback.
Syncs the vendored
public-repo-guardtrio to the canonical source inwave-foundation/scaffolder/public-repo-guard.internal-ipleak rule (Tailscale-CGNAT100.64.0.0/10), lockstep with the pre-publish mirror gateEach changed file is byte-for-byte identical to canonical (verified by git blob SHA). The repo's own
Secrets + content policygate re-scans this PR.🤖 Generated with Claude Code
Note
Update
public-repo-guardworkflow to useactions/checkoutv7 without persisted credentialsSyncs public-repo-guard.yml to the canonical version. Upgrades
actions/checkoutfrom v5.0.1 to v7.0.0 and setspersist-credentials: falseso theGITHUB_TOKENis no longer stored in the repository's Git config after checkout.Macroscope summarized a81a4bd.
Summary by cubic
Syncs the vendored
public-repo-guardwith the canonical source to remove drift and tighten leak detection. Adds an internal IP leak rule and hardens the workflow by updatingactions/checkoutand disabling token persistence.New Features
100.64.0.0/10.Dependencies
actions/checkoutto v7.0.0.persist-credentials: falseto avoid exposing the job token during thegitleaksscan.Written for commit a81a4bd. Summary will update on new commits.