From f1c3d0c39dc46012defb77ebdf37654010707229 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 18:42:53 +0100 Subject: [PATCH] ci(provisioning): don't persist checkout token while caller code runs provision-check.sh runs the caller's ./launcher.sh, so a GITHUB_TOKEN left in .git/config by actions/checkout was readable by caller-controlled code (CodeRabbit on #1113, CWE-522). No later step pushes or fetches, so set persist-credentials: false on both checkouts. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS --- .github/workflows/provisioning-check-reusable.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/provisioning-check-reusable.yml b/.github/workflows/provisioning-check-reusable.yml index ea04c704..789cee32 100644 --- a/.github/workflows/provisioning-check-reusable.yml +++ b/.github/workflows/provisioning-check-reusable.yml @@ -40,6 +40,8 @@ jobs: with: repository: ${{ github.repository }} ref: ${{ github.sha }} + # launcher.sh (caller code) runs below: never leave the token in .git/config. + persist-credentials: false - name: Checkout the provisioning canon uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -47,6 +49,7 @@ jobs: repository: hyperpolymath/standards ref: ${{ job.workflow_sha }} path: .standards-checkout + persist-credentials: false sparse-checkout: | 3-practice/provisioning/templates/build/just sparse-checkout-cone-mode: false