root - chore: defense - disable persist-credentials on non-pushing checkouts - #72
Conversation
…eckouts Stop writing GITHUB_TOKEN into .git/config on tests, release, and code-coverage jobs. Reconcile zizmor as merged in PR #71. Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
There was a problem hiding this comment.
Code Review
This pull request updates the documentation in DEFENSE_IN_DEPTH.md and SECURITY.md to reflect that GitHub Actions workflows are now linted with zizmor on every pull request. There are no review comments, and I have no feedback to provide.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #72 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 3 3
Lines 19 19
Branches 1 1
=========================================
Hits 19 19 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
* root - chore: defense - disable setup-node cache on release Set package-manager-cache: false on the artifact-publishing release workflow so a poisoned Actions cache cannot run in a job that holds publish credentials. Reconcile persist-credentials as merged in PR #72. Co-authored-by: Jared Wray <me@jaredwray.com> * docs: mark setup-node cache disable as PR #73 pending Co-authored-by: Jared Wray <me@jaredwray.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Please check if the PR fulfills these requirements
What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
CI / supply-chain hardening.
Summary
Sets
persist-credentials: falseonactions/checkoutin jobs that never push (defense-in-depth § 4).Status update
DEFENSE_IN_DEPTH.md: persist-credentials → (PR #72 pending); zizmor → PR #71Changes
persist-credentials: falsetotests.yaml,release.yaml, andcode-coverage.yaml(check-workflows.yamlalready had it)SECURITY.mdVerification
actions/checkoutthat does not push now setspersist-credentials: falseReference
defense-in-depth-nodejs § 4