Skip to content

Enforce Least-Privilege Permissions in Container Publishing Workflow - #5

Open
malakasaray-del wants to merge 1 commit into
xrplevm:masterfrom
malakasaray-del:malakasaray-del-patch-1
Open

malakasaray-del wants to merge 1 commit into
xrplevm:masterfrom
malakasaray-del:malakasaray-del-patch-1

Conversation

@malakasaray-del

Copy link
Copy Markdown

Description

This pull request addresses the CI/CD workflow security hygiene finding in blockscout (F-25), identified during the XRPL EVM workspace security audit[cite: 21].

Previously, .github/workflows/publish-docker-image-for-xrplevm.yml lacked an explicit permissions block, relying on default repository-wide token capabilities[cite: 21].

Key Changes & Remediations

Workflow Scoping (F-25 - .github/workflows/publish-docker-image-for-xrplevm.yml)

  • Least-Privilege Scoping: Added explicit job-level permissions strictly bounded to reading code and publishing packages[cite: 21, 35]: ```yaml permissions: contents: read packages: write

Robust Release Version Parsing: Maintained single-match regex isolation (grep -oPm1) for reading RELEASE_VERSION from mix.exs with fail-fast assertions to prevent invalid image builds.

How to Review
Inspect .github/workflows/publish-docker-image-for-xrplevm.yml to verify that permissions: contents: read, packages: write is declared under push_to_registry. Verify YAML syntax validity using Python or standard linting:

python3 -c "import yaml; yaml.safe_load(open('.github/workflows/publish-docker-image-for-xrplevm.yml'))"

### Description
This pull request addresses the CI/CD workflow security hygiene finding in `blockscout` (**F-25**), identified during the XRPL EVM workspace security audit[cite: 21].

Previously, `.github/workflows/publish-docker-image-for-xrplevm.yml` lacked an explicit `permissions` block, relying on default repository-wide token capabilities[cite: 21].

### Key Changes & Remediations

#### Workflow Scoping (F-25 - `.github/workflows/publish-docker-image-for-xrplevm.yml`)
* **Least-Privilege Scoping:** Added explicit job-level permissions strictly bounded to reading code and publishing packages[cite: 21, 35]:
  ```yaml
  permissions:
    contents: read
    packages: write

Robust Release Version Parsing: Maintained single-match regex isolation (grep -oPm1) for reading RELEASE_VERSION from mix.exs with fail-fast assertions to prevent invalid image builds.  

How to Review
Inspect .github/workflows/publish-docker-image-for-xrplevm.yml to verify that permissions: contents: read, packages: write is declared under push_to_registry.  Verify YAML syntax validity using Python or standard linting:

python3 -c "import yaml; yaml.safe_load(open('.github/workflows/publish-docker-image-for-xrplevm.yml'))"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant