From 0768eb39c8dd6a213b435ee0dc42c0035788db57 Mon Sep 17 00:00:00 2001 From: Justin Kovacich Date: Fri, 11 Sep 2026 10:33:27 -0400 Subject: [PATCH] docs: add a security policy, code of conduct, and code owners This repository publishes a reusable workflow that other repositories call, so a change here runs in their CI. It had no disclosure path at all. SECURITY.md states the two facts that make the repo sensitive: consumers pin the mutable `v1` tag, so re-pointing it changes every consumer's CI with no review in their repository; and the release-plz jobs handle the crates.io registry token and the release-plz app credentials, so a workflow change that misuses them can publish under the organization's name. It also records the current pinning posture - dtolnay/rust-toolchain by SHA, the rest by major-version tag - as context for judging a report about a compromised upstream action, rather than leaving a reporter to infer whether that is deliberate. Co-Authored-By: Claude Opus 5 (1M context) --- .github/CODEOWNERS | 5 ++ CODE_OF_CONDUCT.md | 129 +++++++++++++++++++++++++++++++++++++++++++++ SECURITY.md | 59 +++++++++++++++++++++ 3 files changed, 193 insertions(+) create mode 100644 .github/CODEOWNERS create mode 100644 CODE_OF_CONDUCT.md create mode 100644 SECURITY.md diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..45a7d54 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,5 @@ +# Default owners for everything in the repo. Review routing only — the +# main-branch ruleset does not currently require code-owner approval. +# +# Changes here execute in every repository that calls this workflow. +* @luminartech/luv diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..a81db8a --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,129 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, caste, color, religion, or sexual +identity and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +- Demonstrating empathy and kindness toward other people +- Being respectful of differing opinions, viewpoints, and experiences +- Giving and gracefully accepting constructive feedback +- Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +- Focusing on what is best not just for us as individuals, but for the overall + community + +Examples of unacceptable behavior include: + +- The use of sexualized language or imagery, and sexual attention or advances of + any kind +- Trolling, insulting or derogatory comments, and personal or political attacks +- Public or private harassment +- Publishing others' private information, such as a physical or email address, + without their explicit permission +- Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official email address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement at +. All complaints will be reviewed and investigated +promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact**: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence**: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact**: A violation through a single incident or series of +actions. + +**Consequence**: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban + +**Community Impact**: A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence**: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact**: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence**: A permanent ban from any sort of public interaction within the +community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +. + +Community Impact Guidelines were inspired by +[Mozilla's code of conduct enforcement ladder][mozilla]. + +For answers to common questions about this code of conduct, see the FAQ at +. Translations are available at +. + +[homepage]: https://www.contributor-covenant.org +[mozilla]: https://github.com/mozilla/inclusion diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..f2343a8 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,59 @@ +# Security policy + +## Reporting a vulnerability + +Report security issues through GitHub's private vulnerability reporting: open +the [Security tab](https://github.com/luminartech/rust_workflow/security) and +choose **Report a vulnerability**. That opens a private advisory visible only +to the maintainers. + +Please do not open a public issue for a security report. + +## Why this repository is sensitive + +This repository is not a library. It publishes a reusable GitHub Actions +workflow that other repositories call, so a change here executes in their CI. +Two things follow: + +- **Consumers pin a mutable tag.** Callers reference + `rust-ci.yml@v1`, and `v1` is a branch-like tag that moves. Re-pointing it + changes every consumer's CI on their next run, with no action on their part + and no review in their repository. +- **The release path handles publish credentials.** The release-plz jobs + consume `cargo-registry-token`, `release-plz-app-id`, + `release-plz-app-private-key` and `release-plz-token`. A workflow change that + exfiltrates or misuses those can publish crate versions under the + organization's name. + +## Scope + +In scope, and treated as a vulnerability here: + +- Script or expression injection — anything that lets untrusted input (a branch + name, a PR title, issue text) reach a `run:` block or an expression + interpolation. +- Secret exposure — a secret written to logs, to an artifact, to a cache entry, + or made reachable from a `pull_request_target`-style context. +- Excessive token permissions, or a job that keeps `contents: write` where + `contents: read` would do. +- Cache or artifact poisoning that lets one job influence another's inputs. + +Out of scope here, though still worth reporting upstream: + +- Vulnerabilities in the third-party actions this workflow calls. Report those + to their maintainers. +- A consumer repository's own configuration of this workflow. + +## Known posture + +Action pinning is currently mixed: `dtolnay/rust-toolchain` is pinned by commit +SHA, while `actions/checkout`, `actions/setup-python`, `actions/cache`, +`Swatinem/rust-cache`, `taiki-e/install-action`, `actions/upload-artifact` and +`codecov/codecov-action` are pinned by major-version tag, which upstream can +move. This is a deliberate trade-off against the churn of SHA-pinning +everything, not an oversight — but it is the right context for judging a report +about a compromised upstream action. + +Workflows in this repository are linted by +[zizmor](https://github.com/zizmorcore/zizmor) and +[actionlint](https://github.com/rhysd/actionlint) on every pull request.