Skip to content

Commit 00a3171

Browse files
fix(ci): put the write permission on the job that writes, and audit egress
Three findings from the PR head's own checks, all on the gate this PR adds: * Hypatia WH013 (error — this is what fails the Hypatia check): the workflow performs a push/commit/PR but granted no `contents: write` anywhere, so the write would be denied at run time. Fixed by declaring `contents: write` on the relock job, which is the only job that writes. * SonarCloud githubactions:S8233 (MAJOR vulnerability — this is the single issue failing the Quality Gate on this PR): "Move this write permission from workflow level to job level". The workflow-level `pull-requests: write` is now on the relock job too, and the workflow level is `contents: read` only. * Hypatia RE001 (warning, three jobs): any job that reaches for secrets.* should install step-security/harden-runner. Added with `egress-policy: audit` to both gate jobs and to the release job, which holds the release token. actions.lock regenerated for the one new ref: step-security/harden-runner@e14015d5 (v2.21.1), owner 88700172, repo 422287306 — the same ids hyperpolymath/standards records for it. The estate validator now reports 17 refs checked against 17 lockfile keys, 0 errors. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
1 parent e93bf1d commit 00a3171

3 files changed

Lines changed: 36 additions & 1 deletion

File tree

‎.github/workflows/actions-lock.yml‎

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,6 @@ on:
4747

4848
permissions:
4949
contents: read
50-
pull-requests: write
5150

5251
concurrency:
5352
group: actions-lockfile-${{ github.ref }}
@@ -63,13 +62,22 @@ jobs:
6362
name: Verify actions.lock
6463
runs-on: ubuntu-latest
6564
timeout-minutes: 15
65+
permissions:
66+
contents: read
6667
outputs:
6768
# `relock` is computed in the shell, not in an `if:` expression:
6869
# `inputs.mode` is not a recognised named value outside
6970
# workflow_dispatch, and referencing it there is a start-up error.
7071
in_sync: ${{ steps.check.outputs.in_sync }}
7172
relock: ${{ steps.check.outputs.relock }}
7273
steps:
74+
# Egress audit: Hypatia's RE001 asks for it on any job that reaches for
75+
# secrets.*, and both jobs here pass GITHUB_TOKEN to gh.
76+
- name: Harden runner (egress audit)
77+
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
78+
with:
79+
egress-policy: audit
80+
7381
- name: Checkout
7482
id: checkout
7583
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
@@ -147,6 +155,12 @@ jobs:
147155
if: always() && needs.verify.outputs.relock == 'true'
148156
runs-on: ubuntu-latest
149157
timeout-minutes: 20
158+
# The write lives here, on the only job that writes. `contents: write` is
159+
# what lets the PAT-backed push land, and `pull-requests: write` is what
160+
# lets the fallback publish the regenerated file as a comment.
161+
permissions:
162+
contents: write
163+
pull-requests: write
150164
steps:
151165
- name: Decide where the fix goes
152166
id: target
@@ -186,6 +200,13 @@ jobs:
186200
fi
187201
fi
188202
203+
# Egress audit: Hypatia's RE001 asks for it on any job that reaches for
204+
# secrets.*, and both jobs here pass GITHUB_TOKEN to gh.
205+
- name: Harden runner (egress audit)
206+
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
207+
with:
208+
egress-policy: audit
209+
189210
- name: Checkout the branch that needs the lockfile
190211
id: checkout-lock
191212
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

‎.github/workflows/actions.lock‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ workflows:
88
'.github/workflows/actions-lock.yml':
99
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
1010
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
11+
- 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1'
1112
'.github/workflows/boj-build.yml':
1213
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
1314
'.github/workflows/casket-pages.yml':
@@ -44,6 +45,7 @@ workflows:
4445
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
4546
- 'actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c'
4647
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
48+
- 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1'
4749
'.github/workflows/rhodibot.yml':
4850
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
4951
'.github/workflows/scorecard.yml': []
@@ -138,3 +140,8 @@ dependencies:
138140
commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be'
139141
owner_id: 6759885
140142
repo_id: 1352485172
143+
'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1':
144+
ref: 'v2.21.1'
145+
commit: 'sha1-e14015d583714f6e62063499dc959a02595150a1'
146+
owner_id: 88700172
147+
repo_id: 422287306

‎.github/workflows/release.yml‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -100,6 +100,13 @@ jobs:
100100
id-token: write
101101
attestations: write
102102
steps:
103+
# Egress audit. Hypatia's RE001 flags any job that reaches for secrets.*
104+
# without installing harden-runner, and this one holds the release token.
105+
- name: Harden runner (egress audit)
106+
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
107+
with:
108+
egress-policy: audit
109+
103110
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
104111

105112
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1

0 commit comments

Comments
 (0)