Skip to content

ci: adopt harden-runner in standards-only workflows (#941) - #1084

Merged
hyperpolymath merged 4 commits into
mainfrom
fix/baseline-medium-harden-runner
Oct 1, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
fix/baseline-medium-harden-runner

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Owner ruling: adopt step-security/harden-runner. This adds it to the 6 workflows that execute only in standards: apply-workflow-pins, lockfile-drift-detect, propagate-hooks, settings-drift-detect, signed-push-smoke, tag-ruleset-canon.

  • propagate-hooks runs on a protected-branch push, so it uses egress-policy: block with an explicit GitHub endpoint list (Hypatia RE002). The others use audit.
  • actions.lock is hand-updated for those 6 workflows and verified with gh actions-lock --no-fix. The signed-push-smoke local-action failure predates this change.
  • The 6 now-fixed RE001 entries are removed from .hypatia-baseline.json.
  • No allowlist change: StepSecurity is a Marketplace verified creator and the canon policy has verified_allowed: true.

Deliberately not touched: the *-reusable.yml workflows and the consumer-copied labels, label-triage, boj-build and instant-sync. A new action there is a dependency every consumer's actions.lock must list first; otherwise the job fails at startup with no check run.

Verification (local)

  • Hypatia scan of standards: 128 → 121 findings. RE001 in these 6 files is 0, and there is no RE002.
  • actionlint: identical to base on every changed file.

Refs #941.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

Owner ruling 2026-09-30: adopt step-security/harden-runner. This lands
it in the six workflows that execute only in this repo (apply-workflow-
pins, lockfile-drift-detect, propagate-hooks, settings-drift-detect,
signed-push-smoke, tag-ruleset-canon), clearing their RE001 findings.

- propagate-hooks runs on a protected-branch push, so it uses
  egress-policy: block with the GitHub endpoints it actually needs,
  rather than audit (which Hypatia RE002 flags high).
- actions.lock lists harden-runner for those six workflows, and
  `gh actions-lock --no-fix` verifies it (the signed-push-smoke
  local-action failure predates this change).
- The six now-fixed RE001 entries are removed from .hypatia-baseline.json.

The reusable (*-reusable.yml) and consumer-copied workflows (labels,
label-triage, boj-build, instant-sync) are deliberately untouched. A new
action there becomes a dependency that every consumer's actions.lock
must list first, otherwise the job fails at startup with no check run.
No allowlist change is needed: StepSecurity is a Marketplace verified
creator and the canon policy has verified_allowed: true.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 48 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1f1bd6a9-d661-44cc-930a-4aa6fcef1dbc

📥 Commits

Reviewing files that changed from the base of the PR and between 3238461 and a889610.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (10)
  • .github/workflows/apply-workflow-pins.yml
  • .github/workflows/lockfile-drift-detect.yml
  • .github/workflows/propagate-hooks.yml
  • .github/workflows/settings-drift-detect.yml
  • .github/workflows/signed-push-smoke.yml
  • .github/workflows/tag-ruleset-canon.yml
  • .hypatia-baseline.json
  • .machine_readable/REGISTRY.a2ml
  • config/settings/actions-allowlist.json
  • rhodium-standard-repositories/actions-allowlist/allowed-actions.json
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The Allowlist Preflight on this PR reported harden-runner as a GAP:
check-allowed-actions.sh matches `uses:` refs against patterns_allowed
only and does not know which creators are Marketplace-verified, so
`verified_allowed: true` does not satisfy it. Per the allowlist README
("add a pattern here when the estate adopts a new action"), list it in
the canonical allowed-actions.json and in config/settings/
actions-allowlist.json, which set-allowed-actions.sh applies.

Locally: check-allowed-actions.sh reports 0 of 37 refs uncovered.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

hyperpolymath and others added 2 commits October 1, 2026 12:02
Picks up #1088 (main back to green) and the merged #936/#939/#942
fixes so this PR's checks run against the current base.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
allowed-actions.json lives under the RSR spec home, so adding
harden-runner moves that spec's source_hash. Regenerated with
scripts/build-registry.sh; --check, build-registry-test.sh and
build-scorecards.sh --check --strict --verify all pass locally.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@hyperpolymath
hyperpolymath merged commit bd9c319 into main Oct 1, 2026
53 checks passed
@hyperpolymath
hyperpolymath deleted the fix/baseline-medium-harden-runner branch October 1, 2026 12:04
hyperpolymath added a commit that referenced this pull request Oct 1, 2026
…1106 onto main) (#1113)

**Re-land of #1106 onto `main`.** #1106 merged at 15:32Z into its
stacked base `feat/provisioning-canon`, but #1096 (that base) was closed
unmerged. Its content reached `main` as #1112 instead, so the gate never
reached `main`. `.github/workflows/provisioning-check-reusable.yml` is
absent on `main` at `1b6e19ea`.

This is #1106's single commit replayed onto `main` (signed). The
workflow and `canon.lock` are byte-identical to #1106's merged head
`a6649bca`. The only conflict was `.github/workflows/actions.lock`:
#1084 added `harden-runner` under `propagate-hooks.yml` next to where
this PR adds its section, and both are kept. `gh actions-lock --no-fix`
passes 56 of 57 workflows. The one failure is the
`signed-push-smoke.yml` local-action error, which #1084 records as
already failing before this change.

A diff of the `3-practice/provisioning` tree between
`feat/provisioning-canon` and `main` shows that only this gate was
stranded. The template differences there are newer `hypatia:ignore`
annotations that `main` has and the dead base lacks.

KYAML for this workflow follows in a separate PR. That PR first moves
the grep-reading workflow gates (lock-selfcheck, validate-actions-lock,
governance permissions check, duplicate-keys) to `yq` (YAML-POLICY Y-1),
because each of them would falsely fail a flow-style file.

## What

`.github/workflows/provisioning-check-reusable.yml`, the CI gate from
`3-practice/provisioning`. It checks the caller against the canon at the
workflow's own commit (`job.workflow_sha`), in two steps that report
separately:

| Step | Fails when |
|---|---|
| Engine files match the canon | any
`build/just/{provision.just,provision-lib.sh,provision-modes.sh,provision-check.sh}`
is missing or differs byte-for-byte |
| Provisioning set conforms | the **canon** `provision-check.sh`, run
without `--dev`, reports FAIL. It loads `provision-lib.sh` from its own
directory, so a drifted caller copy cannot vouch for itself |

- `channels.scm` is deliberately not compared byte-for-byte:
`toolchain-refresh` re-pins it per repository. `provision-check.sh`
checks its pin instead.
- `just` 1.56.0 comes from the release tarball, pinned by sha256 (the
same pin as launch-scaffolder#67). No new `uses:` is added.
- `actions.lock` gains the section by hand (checkout only). `canon.lock`
lists the reusable as `provisioning` under `[canon.workflows]`.

## Evidence (local dry run of both steps; the CI proof follows on a
throwaway caller)

| Case | cmp step | provision-check |
|---|---|---|
| rsr-template-repo #213 head (control) | pass | pass |
| mutant: `fmt-check` recipe removed | pass | **FAIL** |
| mutant: `python` added to `mise.toml` | pass | **FAIL** (banned tool +
unpinned) |
| mutant: `provision-lib.sh` changed | **FAIL** | pass |
| mutant reverted | pass | pass |

The third mutant is why there are two steps: an engine edit that leaves
conformance intact is caught only by the byte comparison.

## Known, not new

- actionlint does not know the `job.workflow_sha` context. It reports
the same thing 4 times on `allowlist-preflight-reusable.yml`.
- `gh actions-lock` gives this file the same `sha-as-ref` advisory that
every SHA-pinned workflow here carries (94 on the base, 95 with this
one).




🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant