Skip to content

ci(provisioning): don't persist checkout token while caller code runs - #1114

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/provisioning-persist-credentials
Oct 1, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/provisioning-persist-credentials

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Follow-up to #1113. Its hardening commit (11239800) was pushed after automerge was armed. GitHub squash-merged the earlier head 16b0a9b4 at 17:41:00Z, so the commit never reached main. This PR re-applies it unchanged.

What

In .github/workflows/provisioning-check-reusable.yml, both actions/checkout steps now set persist-credentials: false:

  • Caller checkout: the next step runs launcher.sh, which is caller code. With the default persist-credentials: true, the job's GITHUB_TOKEN would sit in .git/config while that code runs.
  • .standards-checkout (canon): the token is never needed after checkout.

Neither checkout pushes or fetches again, so nothing depends on the persisted token.

Verification

  • git diff origin/main --stat: 1 file, 3 insertions.
  • gh actions-lock --no-fix: rc=0. No uses: lines touched.
  • actionlint 1.7.7: rc=1, only on the pre-existing job.workflow_sha lines (50, 89). That is a documented job context property which this actionlint release predates. It is identical on main, not introduced here.

🤖 Generated with Claude Code

https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS

provision-check.sh runs the caller's ./launcher.sh, so a GITHUB_TOKEN left in
.git/config by actions/checkout was readable by caller-controlled code
(CodeRabbit on #1113, CWE-522). No later step pushes or fetches, so set
persist-credentials: false on both checkouts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 1, 2026 17:46
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 48 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 759c59fa-75ae-428c-9ec3-f6f329392dfe

📥 Commits

Reviewing files that changed from the base of the PR and between 89813bf and f1c3d0c.

📒 Files selected for processing (1)
  • .github/workflows/provisioning-check-reusable.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 0187ccd into main Oct 1, 2026
49 checks passed
@hyperpolymath
hyperpolymath deleted the fix/provisioning-persist-credentials branch October 1, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant