chore(ci): update check-permissions action to pull latest - #8437
wise-king-sullyman merged 1 commit into
Conversation
WalkthroughThe PR updates the PR preview workflow to reference the ChangesWorkflow Reference Update
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/pr-preview.yml:
- Around line 9-10: The reusable workflow reference currently uses a mutable ref
"patternfly/.github/.github/workflows/check-team-membership.yml@main"; update
that "uses:" value to a full commit SHA (e.g., replace "`@main`" with the exact
commit hash) so the workflow is pinned and cannot change unexpectedly while
still keeping "secrets: inherit". Locate the "uses:
patternfly/.github/.github/workflows/check-team-membership.yml@main" entry and
substitute the branch ref with the chosen immutable commit SHA.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI (base), Organization UI (inherited)
Review profile: CHILL
Plan: Pro
Run ID: 1ab2c355-77ee-4245-bdc8-34e01205901e
📒 Files selected for processing (1)
.github/workflows/pr-preview.yml
| uses: patternfly/.github/.github/workflows/check-team-membership.yml@main | ||
| secrets: inherit |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
What do GitHub Actions security best practices recommend for reusable workflow uses:references: pinning by branch/tag (e.g.,@main) vs full commit SHA?
💡 Result:
Best practice: prefer pinning reusable workflow uses: references to a full-length commit SHA over pinning to a branch/tag like @main (or @v1). Pinning to a full-length commit SHA is GitHub’s recommended way to make the referenced code effectively immutable, and it’s the only approach GitHub states provides immutable “release” semantics for Actions. [1] What GitHub recommends about branch/tag pins vs commit SHAs 1) Pin to full-length commit SHA for immutability - GitHub docs state: “Pinning an action to a full-length commit SHA is currently the only way to use an action as an immutable release.” [1] - GitHub further explains SHA pinning mitigates risk from a bad actor adding backdoor code to the action’s repository, because they would need to generate a SHA-1 collision for a valid Git object payload. [1] - GitHub also supports enforcing SHA pinning via policy; if a workflow attempts to use an action that isn’t pinned to a full-length SHA, the workflow fails. [2] 2) Pin to a tag only if you trust the creator (and still accept residual risk) - GitHub notes pinning to a tag is more convenient and widely used, but cautions: “Pin actions to a tag only if you trust the action’s creators.” [1] - GitHub adds that tag risk remains even if you trust the author, because a tag “can be moved or deleted” if an attacker gains access to the action’s repository. [1] How this maps specifically to reusable workflows (uses: owner/repo/.github/workflows/...@...) - GitHub’s enterprise policy documentation states: “Require actions to be pinned to a full-length commit SHA… Reusable workflows can still be referenced by tag.” [3] - That implies GitHub recognizes (and policy enforcement may not yet fully constrain) reusable workflows differently than standard Actions. Nevertheless, GitHub also explicitly links reusable-workflow security to the same “good practices” as for third-party workflows. [1] - GitHub’s reusable-workflow configuration docs also state the same conditional guidance: using a commit SHA ensures everyone always uses the same YAML, while tags/branches require trust in that version. [4] Answer to your specific question (pin by branch/tag like @main vs full commit SHA) - If you want the strongest supply-chain and immutability properties: pin the reusable workflow reference to a full-length commit SHA, not @main/tags. [1][4] - If you must use tags/branches: treat that as a weaker control that depends on your trust in the workflow publisher, and understand that tags/branches are mutable and can be moved or deleted (creating a risk window). [1][4] Practical guidance - Prefer: uses: OWNER/REPO/.github/workflows/workflow.yml@<full-commit-sha>. - Avoid: uses: OWNER/REPO/.github/workflows/workflow.yml@main for security-hardening contexts, because it follows a moving reference rather than an immutable one. (GitHub’s immutability guidance is tied to full commit SHAs, while tag/branch references depend on trust and mutability risks.) [1][4]
Citations:
- 1: https://docs.github.com/en/actions/reference/security/secure-use
- 2: https://github.blog/changelog/2025-08-15-github-actions-policy-now-supports-blocking-and-sha-pinning-actions/
- 3: https://githubdocs.cn/en/enterprise-cloud@latest/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise
- 4: https://github.com/github/docs/blob/main/content/actions/concepts/workflows-and-actions/reusing-workflow-configurations.md
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-preview.yml"
if [ -f "$FILE" ]; then
echo "== $FILE =="
nl -ba "$FILE" | sed -n '1,40p'
else
echo "File not found: $FILE" >&2
exit 1
fiRepository: patternfly/patternfly
Length of output: 166
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-preview.yml"
if [ -f "$FILE" ]; then
echo "== $FILE (lines 1-25) =="
cat -n "$FILE" | sed -n '1,25p'
else
echo "File not found: $FILE" >&2
exit 1
fiRepository: patternfly/patternfly
Length of output: 1092
Pin the reusable workflow uses: reference to a full commit SHA (not @main)
.github/workflows/pr-preview.yml uses patternfly/.github/.github/workflows/check-team-membership.yml@main with secrets: inherit, so any upstream change to main can alter the permission gate while still receiving inherited secrets. Pin uses: to an immutable commit SHA.
🔒 Suggested fix
- uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
+ uses: patternfly/.github/.github/workflows/check-team-membership.yml@<full_commit_sha>🧰 Tools
🪛 zizmor (1.25.2)
[warning] 8-10: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[error] 9-9: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[warning] 9-9: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow
(secrets-inherit)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/pr-preview.yml around lines 9 - 10, The reusable workflow
reference currently uses a mutable ref
"patternfly/.github/.github/workflows/check-team-membership.yml@main"; update
that "uses:" value to a full commit SHA (e.g., replace "`@main`" with the exact
commit hash) so the workflow is pinned and cannot change unexpectedly while
still keeping "secrets: inherit". Locate the "uses:
patternfly/.github/.github/workflows/check-team-membership.yml@main" entry and
substitute the branch ref with the chosen immutable commit SHA.
|
Preview: https://pf-pr-8437.surge.sh A11y report: https://pf-pr-8437-a11y.surge.sh |
|
🎉 This PR is included in version 6.6.0-prerelease.2 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Summary by CodeRabbit
Release Notes
This update addresses internal infrastructure and contains no user-facing changes or features.