Skip to content

Commit f7a40a4

Browse files
ci(anchor-drift): stop persisting credentials on all six checkout steps (CWE-522) (#55)
Closes #53. ## What this fixes `.github/workflows/anchor-drift.yml` has **six** `actions/checkout` steps and, on `main`, **zero** `persist-credentials` settings — so all six fall back to the action's default of `true`, leaving the job token in `.git/config` for every subsequent step (CWE-522). No job in this workflow pushes or otherwise uses the token, and it runs on `pull_request` executing repository-controlled code, so the persisted credential is exposure with no upside. ## Why it wasn't fixed in #52 This exact commit (`6a5d1a7`) was written as part of PR #52 but **rejected at push time**, because the acting token then lacked the `workflow` OAuth scope: ``` ! [remote rejected] (refusing to allow an OAuth App to create or update workflow '.github/workflows/anchor-drift.yml' without 'workflow' scope) ``` That rejection fails the *whole* push if any single commit touches a workflow path, so the validator commit landed while this one did not — which is why #52 looked complete and was merged around the gap. The scope has since been granted, so it is cherry-picked here onto current `main`. ## Verification Checked semantically by parsing the YAML rather than grepping, so a comment or a near-miss key cannot pass: ``` YAML parses OK; checkout steps = 6 ; steps still persisting = [] ``` Before, on `main`: 6 checkout steps, 0 `persist-credentials` lines. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01QNjWX2B4FffG7zqMBMui6v Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
1 parent 7b7b379 commit f7a40a4

1 file changed

Lines changed: 36 additions & 0 deletions

File tree

‎.github/workflows/anchor-drift.yml‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,12 @@ jobs:
2222
runs-on: ubuntu-latest
2323
steps:
2424
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
25+
with:
26+
# No job here pushes or uses the token; this workflow runs on
27+
# pull_request and executes repository-controlled code, so the
28+
# default credential persistence in .git/config is exposure with
29+
# no upside (CWE-522).
30+
persist-credentials: false
2531
- name: Check membership manifest and submodule declarations
2632
run: scripts/check-membership.sh
2733
- name: Resolve submodule pins
@@ -52,6 +58,12 @@ jobs:
5258
runs-on: ubuntu-latest
5359
steps:
5460
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
61+
with:
62+
# No job here pushes or uses the token; this workflow runs on
63+
# pull_request and executes repository-controlled code, so the
64+
# default credential persistence in .git/config is exposure with
65+
# no upside (CWE-522).
66+
persist-credentials: false
5567
- name: Check upstream spec and governance pins
5668
run: |
5769
anchor=".machine_readable/anchors/ANCHOR.a2ml"
@@ -69,6 +81,12 @@ jobs:
6981
runs-on: ubuntu-latest
7082
steps:
7183
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
84+
with:
85+
# No job here pushes or uses the token; this workflow runs on
86+
# pull_request and executes repository-controlled code, so the
87+
# default credential persistence in .git/config is exposure with
88+
# no upside (CWE-522).
89+
persist-credentials: false
7290
- uses: hyperpolymath/a2ml-ecosystem/validate-action@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79
7391
with:
7492
path: "."
@@ -88,6 +106,12 @@ jobs:
88106
runs-on: ubuntu-latest
89107
steps:
90108
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
109+
with:
110+
# No job here pushes or uses the token; this workflow runs on
111+
# pull_request and executes repository-controlled code, so the
112+
# default credential persistence in .git/config is exposure with
113+
# no upside (CWE-522).
114+
persist-credentials: false
91115
- uses: hyperpolymath/a2ml-ecosystem/validate-action@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79
92116
with:
93117
path: "conformance/valid"
@@ -97,6 +121,12 @@ jobs:
97121
runs-on: ubuntu-latest
98122
steps:
99123
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
124+
with:
125+
# No job here pushes or uses the token; this workflow runs on
126+
# pull_request and executes repository-controlled code, so the
127+
# default credential persistence in .git/config is exposure with
128+
# no upside (CWE-522).
129+
persist-credentials: false
100130
- id: negative
101131
continue-on-error: true
102132
uses: hyperpolymath/a2ml-ecosystem/validate-action@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79
@@ -118,5 +148,11 @@ jobs:
118148
runs-on: ubuntu-latest
119149
steps:
120150
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
151+
with:
152+
# No job here pushes or uses the token; this workflow runs on
153+
# pull_request and executes repository-controlled code, so the
154+
# default credential persistence in .git/config is exposure with
155+
# no upside (CWE-522).
156+
persist-credentials: false
121157
- name: Deed fixtures — all four ruled heads
122158
run: bash conformance/run-deed-tests.sh

0 commit comments

Comments
 (0)