Repository navigation
ci: adopt harden-runner in standards-only workflows (#941) - #1084
Merged
Merged
Conversation
Owner ruling 2026-09-30: adopt step-security/harden-runner. This lands it in the six workflows that execute only in this repo (apply-workflow- pins, lockfile-drift-detect, propagate-hooks, settings-drift-detect, signed-push-smoke, tag-ruleset-canon), clearing their RE001 findings. - propagate-hooks runs on a protected-branch push, so it uses egress-policy: block with the GitHub endpoints it actually needs, rather than audit (which Hypatia RE002 flags high). - actions.lock lists harden-runner for those six workflows, and `gh actions-lock --no-fix` verifies it (the signed-push-smoke local-action failure predates this change). - The six now-fixed RE001 entries are removed from .hypatia-baseline.json. The reusable (*-reusable.yml) and consumer-copied workflows (labels, label-triage, boj-build, instant-sync) are deliberately untouched. A new action there becomes a dependency that every consumer's actions.lock must list first, otherwise the job fails at startup with no check run. No allowlist change is needed: StepSecurity is a Marketplace verified creator and the canon policy has verified_allowed: true. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
Contributor
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 48 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (10)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The Allowlist Preflight on this PR reported harden-runner as a GAP:
check-allowed-actions.sh matches `uses:` refs against patterns_allowed
only and does not know which creators are Marketplace-verified, so
`verified_allowed: true` does not satisfy it. Per the allowlist README
("add a pattern here when the estate adopts a new action"), list it in
the canonical allowed-actions.json and in config/settings/
actions-allowlist.json, which set-allowed-actions.sh applies.
Locally: check-allowed-actions.sh reports 0 of 37 refs uncovered.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
Contributor
|
Autopilot could not be updated. Open Coding to check access and billing. |
Picks up #1088 (main back to green) and the merged #936/#939/#942 fixes so this PR's checks run against the current base. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
allowed-actions.json lives under the RSR spec home, so adding harden-runner moves that spec's source_hash. Regenerated with scripts/build-registry.sh; --check, build-registry-test.sh and build-scorecards.sh --check --strict --verify all pass locally. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
hyperpolymath
added a commit
that referenced
this pull request
Oct 1, 2026
…1106 onto main) (#1113) **Re-land of #1106 onto `main`.** #1106 merged at 15:32Z into its stacked base `feat/provisioning-canon`, but #1096 (that base) was closed unmerged. Its content reached `main` as #1112 instead, so the gate never reached `main`. `.github/workflows/provisioning-check-reusable.yml` is absent on `main` at `1b6e19ea`. This is #1106's single commit replayed onto `main` (signed). The workflow and `canon.lock` are byte-identical to #1106's merged head `a6649bca`. The only conflict was `.github/workflows/actions.lock`: #1084 added `harden-runner` under `propagate-hooks.yml` next to where this PR adds its section, and both are kept. `gh actions-lock --no-fix` passes 56 of 57 workflows. The one failure is the `signed-push-smoke.yml` local-action error, which #1084 records as already failing before this change. A diff of the `3-practice/provisioning` tree between `feat/provisioning-canon` and `main` shows that only this gate was stranded. The template differences there are newer `hypatia:ignore` annotations that `main` has and the dead base lacks. KYAML for this workflow follows in a separate PR. That PR first moves the grep-reading workflow gates (lock-selfcheck, validate-actions-lock, governance permissions check, duplicate-keys) to `yq` (YAML-POLICY Y-1), because each of them would falsely fail a flow-style file. ## What `.github/workflows/provisioning-check-reusable.yml`, the CI gate from `3-practice/provisioning`. It checks the caller against the canon at the workflow's own commit (`job.workflow_sha`), in two steps that report separately: | Step | Fails when | |---|---| | Engine files match the canon | any `build/just/{provision.just,provision-lib.sh,provision-modes.sh,provision-check.sh}` is missing or differs byte-for-byte | | Provisioning set conforms | the **canon** `provision-check.sh`, run without `--dev`, reports FAIL. It loads `provision-lib.sh` from its own directory, so a drifted caller copy cannot vouch for itself | - `channels.scm` is deliberately not compared byte-for-byte: `toolchain-refresh` re-pins it per repository. `provision-check.sh` checks its pin instead. - `just` 1.56.0 comes from the release tarball, pinned by sha256 (the same pin as launch-scaffolder#67). No new `uses:` is added. - `actions.lock` gains the section by hand (checkout only). `canon.lock` lists the reusable as `provisioning` under `[canon.workflows]`. ## Evidence (local dry run of both steps; the CI proof follows on a throwaway caller) | Case | cmp step | provision-check | |---|---|---| | rsr-template-repo #213 head (control) | pass | pass | | mutant: `fmt-check` recipe removed | pass | **FAIL** | | mutant: `python` added to `mise.toml` | pass | **FAIL** (banned tool + unpinned) | | mutant: `provision-lib.sh` changed | **FAIL** | pass | | mutant reverted | pass | pass | The third mutant is why there are two steps: an engine edit that leaves conformance intact is caught only by the byte comparison. ## Known, not new - actionlint does not know the `job.workflow_sha` context. It reports the same thing 4 times on `allowlist-preflight-reusable.yml`. - `gh actions-lock` gives this file the same `sha-as-ref` advisory that every SHA-pinned workflow here carries (94 on the base, 95 with this one). 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Owner ruling: adopt
step-security/harden-runner. This adds it to the 6 workflows that execute only in standards: apply-workflow-pins, lockfile-drift-detect, propagate-hooks, settings-drift-detect, signed-push-smoke, tag-ruleset-canon.propagate-hooksruns on a protected-branch push, so it usesegress-policy: blockwith an explicit GitHub endpoint list (Hypatia RE002). The others useaudit.actions.lockis hand-updated for those 6 workflows and verified withgh actions-lock --no-fix. The signed-push-smoke local-action failure predates this change..hypatia-baseline.json.verified_allowed: true.Deliberately not touched: the
*-reusable.ymlworkflows and the consumer-copied labels, label-triage, boj-build and instant-sync. A new action there is a dependency every consumer'sactions.lockmust list first; otherwise the job fails at startup with no check run.Verification (local)
Refs #941.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65