Repository navigation
fix(ci): restore reachable standards workflow pins #48
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -18,5 +18,5 @@ permissions: | |
| contents: read | ||
| jobs: | ||
| scan: | ||
| uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 | ||
| uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@092dedada188f56c5915f74a5fd40aac093742c3 | ||
| secrets: inherit | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow diff ---'
git diff -- .github/workflows/secret-scanner.yml
printf '%s\n' '--- caller workflow ---'
cat -n .github/workflows/secret-scanner.yml
printf '%s\n' '--- reusable workflow references ---'
rg -n --hidden --glob '.github/workflows/**' '092deda|secret-scanner|workflow_call|secrets:' .Repository: hyperpolymath/aggregate-library Length of output: 2016 🤖 get_repo_knowledge executed:
Length of output: 2007 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow files ---'
git ls-files '.github/workflows'
printf '%s\n' '--- caller workflow ---'
cat -n .github/workflows/secret-scanner.yml
printf '%s\n' '--- matching reusable workflow references ---'
rg -n --hidden --glob '.github/workflows/**' '092deda|secret-scanner|workflow_call|secrets:' .Repository: hyperpolymath/aggregate-library Length of output: 2365 🏁 Script executed: #!/bin/bash
set -eu
sha='092dedada188f56c5915f74a5fd40aac093742c3'
url="https://raw.githubusercontent.com/hyperpolymath/standards/${sha}/.github/workflows/secret-scanner-reusable.yml"
printf '%s\n' '--- pinned reusable workflow ---'
curl -fsSL "$url" | cat -n
printf '%s\n' '--- pinned commit identity ---'
curl -fsSL "https://api.github.com/repos/hyperpolymath/standards/commits/${sha}" |
jq -r '[.sha, .commit.message] | `@tsv`'Repository: hyperpolymath/aggregate-library Length of output: 50387 🌐 Web query:
💡 Result: In GitHub Actions, reusable workflows do not automatically inherit secrets, including the Citations:
🏁 Script executed: #!/bin/bash
set -eu
sha='092dedada188f56c5915f74a5fd40aac093742c3'
url="https://raw.githubusercontent.com/hyperpolymath/standards/${sha}/.github/workflows/secret-scanner-reusable.yml"
printf '%s\n' '--- workflow_call contract ---'
curl -fsSL "$url" | sed -n '88,115p' | cat -n
printf '%s\n' '--- secret references and token consumers ---'
curl -fsSL "$url" |
grep -nE 'secrets(\.|:)|GITHUB_TOKEN|token|gitleaks' |
head -80Repository: hyperpolymath/aggregate-library Length of output: 6335 🌐 Web query:
💡 Result: In GitHub Actions, you do not need to explicitly pass the GITHUB_TOKEN to a reusable workflow, nor do you need to use the secrets: inherit keyword for it [1][2]. A called (reusable) workflow is automatically granted access to the GITHUB_TOKEN, which remains available via the secrets.GITHUB_TOKEN or github.token context [1][2][3]. Regarding the broader handling of secrets with reusable workflows: 1. Automatic GITHUB_TOKEN Access: You do not need to map the GITHUB_TOKEN in the on.workflow_call.secrets section of your reusable workflow, nor do you need to pass it in the jobs.<job_id>.secrets block of your caller workflow [1][2]. 2. Passing Custom Secrets: If you need to pass custom (non-GITHUB_TOKEN) secrets to a reusable workflow, you have two primary options: - Explicit Mapping: Define the secrets in the reusable workflow using on.workflow_call.secrets and pass them individually in the caller workflow using jobs.<job_id>.secrets [4][5]. - Inherit All: Use secrets: inherit in the caller workflow to pass all secrets available to the caller to the reusable workflow [6][7]. Note that this keyword is only supported for workflows within the same organization or enterprise [6][8]. 3. Security and Permissions: While the reusable workflow has automatic access to the GITHUB_TOKEN, its permissions are governed by the jobs.<job_id>.permissions block in the caller workflow [1][2]. You can downgrade these permissions in the caller, but they cannot be elevated in the called workflow [1][2]. If no permissions are specified in the caller job, the called workflow uses the default GITHUB_TOKEN permissions [1][2]. Citations:
Remove The pinned workflow declares no secrets and does not use 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win
Document why
actions: readis required.Add a YAML comment above this permission. State that the pinned governance reusable workflow requires it to start. This explains the deliberate permission grant and helps reviewers maintain the least-privilege boundary when the reusable workflow changes.
Proposed change
+ # Required by the pinned governance reusable workflow to start. actions: read[minor]
📝 Committable suggestion
🧰 Tools
🪛 zizmor (1.29.0)
[warning] 12-12: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment
(undocumented-permissions)
🤖 Prompt for AI Agents
Source: Linters/SAST tools