Repository navigation
chore: R-16 toolchain pin + reconciliation #89
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
0a28952
5763810
9249075
381d3b4
4225512
5a8a923
01c2f21
2c1beed
a457a8b
ac91e9d
03a4468
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,7 @@ on: | |
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| pages: write | ||
| id-token: write | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -18,6 +18,7 @@ concurrency: | |
| cancel-in-progress: true | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -13,6 +13,7 @@ on: | |
| branches: [main, master] | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -19,6 +19,7 @@ on: | |
| types: [created] | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -8,6 +8,7 @@ on: | |
| branches: [ "main" ] | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -9,6 +9,7 @@ on: | |
| types: [published] | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -13,6 +13,7 @@ concurrency: | |
| cancel-in-progress: true | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
|
||
| jobs: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,7 @@ name: Push email notification | |
| on: | ||
| push: {} | ||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| jobs: | ||
| notify: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -8,10 +8,11 @@ on: | |
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| security-events: write | ||
| id-token: write | ||
|
Comment on lines
+11
to
+12
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: # Inspect the workflow-level and job-level permission declarations, plus the
# reusable-workflow call that consumes them.
cat -n .github/workflows/scorecard.ymlRepository: hyperpolymath/sanctify-php Length of output: 713 🌐 Web query:
💡 Result: In GitHub Actions, GITHUB_TOKEN permissions can be configured at both the workflow level and the job level, with job-level configurations acting as explicit overrides [1][2]. Workflow-Level vs. Job-Level Permissions When you define the permissions key at the top level of a workflow, those settings apply to all jobs within that workflow [1][3]. If you define the permissions key within an individual job, that job-level configuration completely overrides the workflow-level settings for that specific job [1][2]. Permissions are not merged; if you define job-level permissions, you must explicitly declare all required permissions for that job, as any unspecified permissions will default to none [1]. Reusable Workflows When using reusable workflows, the permissions are handled as follows: 1. Inheritance: If jobs.<job_id>.permissions is not specified in the calling job, the called (reusable) workflow defaults to the repository's default GITHUB_TOKEN permissions [4][5]. 2. Restriction (Downgrade Only): Permissions passed from a caller workflow to a reusable workflow can be maintained or downgraded (made more restrictive), but they cannot be elevated [4][5]. 3. Nested Chains: In a chain of nested reusable workflows (e.g., A > B > C), permissions can only be maintained or reduced throughout the chain [4][6]. A called workflow cannot be granted a permission that was not already granted by the caller [5][7]. Best Practices To adhere to the principle of least privilege, it is generally recommended to define permissions at the job level [2][8]. This avoids granting broad permissions across the entire workflow and makes it clearer which jobs require specific access [2]. If a workflow has only one job, defining permissions at the job level is still considered a best practice for consistency and future-proofing [8]. Citations:
Remove the redundant workflow-level write permissions. The 🧰 Tools🪛 zizmor (1.29.0)[warning] 11-11: overly broad permissions (excessive-permissions): security-events: write is overly broad at the workflow level (excessive-permissions) [error] 12-12: overly broad permissions (excessive-permissions): id-token: write is overly broad at the workflow level (excessive-permissions) [warning] 11-11: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment (undocumented-permissions) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
| jobs: | ||
| scorecard: | ||
| uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 | ||
| uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@5b1d00229e5e8c0c0fbfedc7e80f37ea50f49236 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
repo='https://github.com/hyperpolymath/standards.git'
sha='5b1d00229e5e8c0c0fbfedc7e80f37ea50f49236'
tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT
test -n "$(git ls-remote "$repo" "$sha")"
git -C "$tmp" init -q
git -C "$tmp" remote add origin "$repo"
git -C "$tmp" fetch --depth=1 origin "$sha"
for path in \
.github/workflows/scorecard-reusable.yml \
.github/workflows/mirror-reusable.yml
do
git -C "$tmp" show "$sha:$path" | grep -qE '^[[:space:]]*workflow_call:'
doneRepository: hyperpolymath/sanctify-php Length of output: 164 🏁 Script executed: set -u
sha='5b1d00229e5e8c0c0fbfedc7e80f37ea50f49236'
repo='https://github.com/hyperpolymath/standards.git'
printf '%s\n' '== pinned object =='
git ls-remote "$repo" "$sha" || true
for path in \
.github/workflows/scorecard-reusable.yml \
.github/workflows/mirror-reusable.yml
do
printf '\n== %s at %s ==\n' "$path" "$sha"
curl -fsSL --max-time 20 \
"https://raw.githubusercontent.com/hyperpolymath/standards/$sha/$path" \
| sed -n '1,220p' || true
done
printf '\n== callers ==\n'
for path in .github/workflows/scorecard.yml .github/workflows/mirror.yml
do
printf '\n-- %s --\n' "$path"
sed -n '1,100p' "$path"
doneRepository: hyperpolymath/sanctify-php Length of output: 1284 🏁 Script executed: set -u
repo_api='https://api.github.com/repos/hyperpolymath/standards'
sha='5b1d00229e5e8c0c0fbfedc7e80f37ea50f49236'
printf '%s\n' '== commit lookup =='
curl -sS --max-time 20 -w '\nHTTP %{http_code}\n' \
"$repo_api/commits/$sha" | sed -n '1,40p'
printf '%s\n' '== tree lookup =='
curl -sS --max-time 20 -w '\nHTTP %{http_code}\n' \
"$repo_api/git/trees/$sha?recursive=1" | sed -n '1,60p'Repository: hyperpolymath/sanctify-php Length of output: 588 Replace the invalid reusable-workflow pin.
📍 Affects 2 files
🤖 Prompt for AI Agents |
||
| permissions: | ||
| contents: read | ||
| security-events: write | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -11,6 +11,7 @@ on: | |
| - '.github/workflows/**' | ||
|
|
||
| permissions: read-all | ||
| actions: read | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -e
file=".github/workflows/workflow-linter.yml"
printf '%s\n' '--- workflow excerpt ---'
sed -n '1,35p' "$file"
printf '%s\n' '--- tracked diff for workflow ---'
git diff -- "$file"
printf '%s\n' '--- workflow file type and YAML-related checks ---'
file "$file"
command -v yamllint || trueRepository: hyperpolymath/sanctify-php Length of output: 1199 Fix the invalid
🧰 Tools🪛 YAMLlint (1.37.1)[error] 14-14: syntax error: mapping values are not allowed here (syntax) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
|
|
||
| jobs: | ||
| lint-workflows: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,2 @@ | ||
| [tools] | ||
| just = "1.36.0" |
This file was deleted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Document or remove the newly added
actions: readpermissions.Add an accurate inline comment identifying the Actions API consumer, or remove the permission where no consumer exists.
.github/workflows/boj-build.yml#L19-L19.github/workflows/casket-pages.yml#L10-L10.github/workflows/codeql.yml#L21-L21.github/workflows/dependabot-automerge.yml#L44-L44.github/workflows/mirror.yml#L10-L10.github/workflows/dogfood-gate.yml#L16-L16.github/workflows/generator-generic-ossf-slsa3-publish.yml#L22-L22.github/workflows/haskell.yml#L11-L11.github/workflows/instant-sync.yml#L12-L12.github/workflows/pages.yml#L8-L8.github/workflows/php-security.yml#L16-L16.github/workflows/push-email-notify.yml#L10-L10📍 Affects 2 files
.github/workflows/boj-build.yml#L19-L19(this comment).github/workflows/dogfood-gate.yml#L16-L16🤖 Prompt for AI Agents
Source: Linters/SAST tools