From 65e9b8ab97688080c672322174721814fd94fc24 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Sun, 13 Sep 2026 15:58:22 +0000 Subject: [PATCH] Disable persisted credentials in auto-upgrade checkout Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/agentic-auto-upgrade.yml | 2 ++ pkg/workflow/auto_update_workflow.go | 2 ++ pkg/workflow/auto_update_workflow_test.go | 1 + 3 files changed, 5 insertions(+) diff --git a/.github/workflows/agentic-auto-upgrade.yml b/.github/workflows/agentic-auto-upgrade.yml index 10fca8f7a1e..5c8e1d88b1c 100644 --- a/.github/workflows/agentic-auto-upgrade.yml +++ b/.github/workflows/agentic-auto-upgrade.yml @@ -47,6 +47,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 diff --git a/pkg/workflow/auto_update_workflow.go b/pkg/workflow/auto_update_workflow.go index 9b5f9e21157..8f2e26db605 100644 --- a/pkg/workflow/auto_update_workflow.go +++ b/pkg/workflow/auto_update_workflow.go @@ -225,6 +225,8 @@ jobs: steps: - name: Checkout repository uses: ` + getActionPin("actions/checkout") + ` + with: + persist-credentials: false ` + installCLISteps + ` - name: Setup Scripts uses: ` + setupActionRef + ` diff --git a/pkg/workflow/auto_update_workflow_test.go b/pkg/workflow/auto_update_workflow_test.go index f1ca50a62fe..03a0c825ea7 100644 --- a/pkg/workflow/auto_update_workflow_test.go +++ b/pkg/workflow/auto_update_workflow_test.go @@ -37,6 +37,7 @@ func TestGenerateAutoUpdateWorkflow_Enabled(t *testing.T) { assert.Contains(t, content, "GH_AW_OPERATION: upgrade", "should set upgrade operation") assert.Contains(t, content, "GH_AW_CMD_PREFIX: ./gh-aw", "should use dev CLI prefix by default") assert.Contains(t, content, "Checkout repository", "should include checkout step") + assert.Contains(t, content, "persist-credentials: false", "should not persist checkout credentials") assert.Contains(t, content, "Build gh-aw", "should include local gh-aw build step in dev mode") assert.Contains(t, content, "mainNotifyIssue", "should call mainNotifyIssue") assert.NotContains(t, content, "uses: ./.github/workflows/agentics-maintenance.yml", "should not use workflow_call")