Repository navigation
fix(ci): enforce least-privilege GitHub Actions token permissions - #1011
ANAMASGARD wants to merge 1 commit into
Conversation
Declare read-only defaults across GitHub Actions workflows and pass required job scopes through reusable workflow callers. Limit CodeQL, benchmark comments, release creation, and image attestation to their required permissions. Fixes kubescape#995 Signed-off-by: Gaurav Chaudhary <chaudharygaurav2004@gmail.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughNine GitHub Actions workflows now set workflow-level ChangesWorkflow token permissions
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The reviewed changes have no demonstrated workflow regression. The possible permission expansion for PR-driven jobs depends on repository settings that are not established here, so no concrete merge blocker is confirmed. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The changes narrow several permissions, but release-triggered benchmarks gain pull-request write access even though their comment step does not run for that event. This modestly increases the impact of compromised benchmark execution. The merged-main trigger limits exposure, and live execution and previous default token settings remain unverified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
matthyx
left a comment
There was a problem hiding this comment.
Reviewed 8863e2312d97c3bf3f6d90c9a92597deedf4e3c7 against main at 67e455e040520a3f1f5a4ac20fbf5fe25f676d43. Verdict: needs clarification; no confirmed correctness blocker found.
The hardening is needed for #995: parsing the target finds nine of ten workflows without top-level permissions; the head has none missing. All five local reusable-workflow edges have compatible explicit job scopes. Release creation keeps contents-write, Quay uses registry credentials, and private E2E operations use the App token. The pinned attestation action documents artifact-metadata-write for storage records; its absence previously produced a warning, not necessarily an attestation failure.
History: #135 proposed read-all in two workflows and closed unmerged, with no documented maintainer rejection. #778 removed benchmark job permissions to fix a release startup failure; this PR addresses that objection by updating both callers. #710 and #833 are incorporated permission/provenance predecessors. Open #1015 overlaps workflow files but pins actions rather than replacing this change. Searches across PR states and issues used permissions, read-all, Token-Permissions, benchmark, CodeQL and startup_failure, capped at 100/query; the broad benchmark search hit that cap. No superseding fix found within those limits.
Validation: git diff --check passed. YAML parsing and a caller/callee permission-map check passed. actionlint -shellcheck= -pyflakes= -oneline reported the same eight diagnostics on base and head, with no new findings. The component suite and pin check succeeded for this exact head. Go tests, Scorecard, release, benchmark and CodeQL execution were not run locally; repository scripts were not executed. The green checks do not validate the changed release/CodeQL chains because their triggers exclude workflow-only changes. No inline threads or human reviews were present when rechecked.
Two points before approval:
- Please confirm
mainis the intended target despite the repository PR template requestingdevfor non-documentation changes. - Please provide evidence validating the changed release and CodeQL permission paths, or maintainer confirmation of an acceptable static-validation gate for this workflow-only change. The description's statement that no workflows ran should also be updated to distinguish the successful component/pin checks from these untested paths.
The unused PR-write capability on the release benchmark is a nonblocking architecture WATCH already covered by CodeRabbit; I am not duplicating that feedback. No source changes or merge actions were performed.
Overview
Add
permissions: read-alldefaults to all GitHub Actions workflows that lacked them. Grant required permissions at the job level and pass them through reusable workflow callers for CodeQL uploads, benchmark PR comments, release creation, image signing, and attestation.Remove unnecessary package-write and PR permissions, and grant artifact-metadata access required by the pinned attestation action.
Fixes #995
How to Test
Token-Permissions: reproduced 0/10 before the changes and verified 10/10 afterward.git diff --checkpassed.Live GitHub Actions execution has not been verified: pushing the branch did not trigger any workflows.
Checklist before requesting a review
The unchecked items do not apply to this workflow-permissions change; validation is described above.