root - chore: defense - stage npm publishes from packed tarballs - #74
Conversation
Switch release.yaml from live pnpm publish to pack + pnpm stage publish so a CI run can only stage. Reconcile setup-node cache as PR #73 and record that workflows do not use npm registry tokens (OIDC id-token). Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
There was a problem hiding this comment.
Code Review
This pull request updates the security documentation in DEFENSE_IN_DEPTH.md and SECURITY.md to reflect that the release workflow disables package-manager caching and uses OIDC instead of npm tokens. However, the reviewer correctly pointed out that the actual workflow file changes (such as .github/workflows/release.yaml) are missing from this pull request and should be included.
| - Dependencies install through pnpm with a 7-day cooldown on new versions, lifecycle scripts blocked by default, `trustPolicy: no-downgrade`, and exotic subdependencies blocked. | ||
| - The lockfile is committed and CI installs with `--frozen-lockfile`. There is no Dependabot config; dependency updates go through reviewed PRs. | ||
| - CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI; every action is pinned to a full commit SHA; Socket Firewall (`sfw`) wraps `pnpm install`; zizmor lints workflows on every PR; checkouts that do not push set `persist-credentials: false`. | ||
| - The release workflow disables `setup-node` package-manager caching. Workflows do not use npm or registry tokens; publish authenticates with OIDC. |
There was a problem hiding this comment.
The pull request title and description state that the release workflow is being updated to use pnpm pack and pnpm stage publish instead of pnpm publish. However, the actual workflow files (such as .github/workflows/release.yaml) are not included in the changes for this pull request. Only DEFENSE_IN_DEPTH.md and SECURITY.md are modified. Please include the missing workflow file changes in this pull request if they were intended to be part of this work.
There was a problem hiding this comment.
The workflow change is in this PR. .github/workflows/release.yaml is modified on the first commit (e266c06): Pack + pnpm stage publish ./packed/*.tgz --access public --provenance --no-git-checks replaces live pnpm publish. The second commit only updates DEFENSE_IN_DEPTH.md with the pending PR number, which is likely what this review looked at in isolation.
Files in the PR: .github/workflows/release.yaml, DEFENSE_IN_DEPTH.md, SECURITY.md.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #74 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 3 3
Lines 19 19
Branches 1 1
=========================================
Hits 19 19 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: df2908d255
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - [ ] Artifact-publishing workflows disable `actions/setup-node` default caching (`package-manager-cache: false`) to prevent cache poisoning (PR #73 pending) | ||
| - [ ] No npm tokens (or other registry credentials) in Actions secrets | ||
| - [x] Artifact-publishing workflows disable `actions/setup-node` default caching (`package-manager-cache: false`) to prevent cache poisoning — PR #73 | ||
| - [x] No npm tokens (or other registry credentials) in Actions secrets — verified 2026-09-09 (no NPM_TOKEN/NODE_AUTH_TOKEN in workflow YAML; publish uses OIDC `id-token`) |
There was a problem hiding this comment.
Keep the registry-secret check unverified
The inspected .github/workflows/*.yaml files establish only that no workflow references NPM_TOKEN or NODE_AUTH_TOKEN; they cannot show whether those server-side Actions secrets still exist. Marking this control complete can leave reusable registry credentials configured while future reviewers believe they were removed, so keep it pending until the repository/environment secrets are inspected and any registry credentials are deleted.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Agreed. Workflow YAML only shows that no job uses NPM_TOKEN / NODE_AUTH_TOKEN; this token cannot list repository or org Actions secrets (403). I’ve unchecked the catalog item and dropped that claim from SECURITY.md. It stays pending until someone with secrets:read inspects (and deletes) leftover registry credentials.
Codex is right that workflow YAML cannot prove Actions secrets are empty. Keep the catalog item pending until secrets:read can inspect them. Co-authored-by: Jared Wray <me@jaredwray.com>
* root - chore: defense - gate stage-publish on Aikido scan-release Add a scan-release job that runs aikido-api-client scan-release and make the existing pack/stage job need it. Reconcile staged publishing as PR #74. Co-authored-by: Jared Wray <me@jaredwray.com> * docs: mark Aikido scan-release gate as PR #75 pending Co-authored-by: Jared Wray <me@jaredwray.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Please check if the PR fulfills these requirements
What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
CI / supply-chain hardening.
Summary
Switches the existing
releaseworkflow to pack a tarball andpnpm stage publishinstead of livepnpm publish(defense-in-depth § 5).Status update
DEFENSE_IN_DEPTH.md: stage publish → (PR #74 pending); setup-node cache → PR #73; no npm tokens in Actions secrets → left unchecked (workflows have no refs; secrets list 403)Changes
pnpm publishwithpnpm packintopacked/thenpnpm stage publish ./packed/*.tgz --access public --provenance --no-git-checkspnpm/action-setup,test:ci, OIDCid-token). Aikidoscan-releaseis a later § 6 item, not this PR.package-manager-cache: falseas merged in PR root - chore: defense - disable setup-node cache on release #73NPM_TOKEN/NODE_AUTH_TOKEN, but this token cannot list secrets (403). Please inspect repo/org secrets and delete any leftover npm/registry credentials.Verification
pnpm stage publish ./packed/*.tgz --no-git-checksNPM_TOKEN/NODE_AUTH_TOKENin.github/workflows/Reference
defense-in-depth-nodejs § 5