Skip to content

chore(guard): sync vendored public-repo-guard to canonical - #19

Open
wave-av-release-bot[bot] wants to merge 1 commit into
mainfrom
chore/guard-canonical-sync
Open

chore(guard): sync vendored public-repo-guard to canonical#19
wave-av-release-bot[bot] wants to merge 1 commit into
mainfrom
chore/guard-canonical-sync

Conversation

@wave-av-release-bot

@wave-av-release-bot wave-av-release-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

Syncs the vendored public-repo-guard trio to the canonical source in wave-foundation/scaffolder/public-repo-guard.

  • adds the internal-ip leak rule (Tailscale-CGNAT 100.64.0.0/10), lockstep with the pre-publish mirror gate
  • reconciles accumulated drift in the vendored copy

Each changed file is byte-for-byte identical to canonical (verified by git blob SHA). The repo's own Secrets + content policy gate re-scans this PR.

🤖 Generated with Claude Code


Open in Devin Review

Note

Update public-repo-guard workflow to use actions/checkout v7 without persisted credentials

Syncs public-repo-guard.yml to the canonical version. Upgrades actions/checkout from v5.0.1 to v7.0.0 and sets persist-credentials: false so the GITHUB_TOKEN is no longer stored in the repository's Git config after checkout.

Macroscope summarized 921f176.


Summary by cubic

Syncs the vendored public-repo-guard with wave-foundation/scaffolder/public-repo-guard to keep rules and CI in lockstep. Adds the internal-ip leak rule (Tailscale CGNAT 100.64.0.0/10) and hardens the workflow by moving to actions/checkout@v7 with persist-credentials: false; changes are byte-for-byte identical to canonical.

Written for commit 921f176. Summary will update on new commits.

Review in cubic

@greptile-apps

greptile-apps Bot commented Aug 4, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@macroscopeapp

macroscopeapp Bot commented Aug 4, 2026

Copy link
Copy Markdown

Approvability

Verdict: Needs human review

Unable to check for correctness in 921f176. This PR updates the actions/checkout version and adds security hardening (persist-credentials: false) to the public-repo-guard workflow. While the changes are beneficial and low-risk, the file is owned by wave-av/streaming-team and the bot author is not a designated owner, so the owning team should review.

You can customize Macroscope's approvability policy. Learn more.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 potential issues.

Open in Devin Review

Comment on lines +45 to +53
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
# Checkout defaults to persisting the job token for later steps: since v6 it
# lives in a file under $RUNNER_TEMP referenced from .git/config, no longer in
# .git/config itself. It is still a live credential in the job, and this job
# downloads a third-party binary (gitleaks, below) and runs it over the whole
# tree. Nothing here pushes -- the scan is `--no-git` over the working tree --
# so no step needs authenticated Git; drop it. (zizmor: artipacked)
persist-credentials: false

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Change log not updated for this change

The project's contribution rules require every pull request to add an entry under the "Unreleased" heading of the change log, but this change updates the security-gate workflow (.github/workflows/public-repo-guard.yml:45-53) without adding any note there.
Impact: The release notes will be missing a record of this update, so maintainers tracking changes will not see it.

Rule source and current state of the change log

CONTRIBUTING.md under "PR shape" states: "Update CHANGELOG.md under the unreleased heading." The ## [Unreleased] section in CHANGELOG.md is currently empty and no change-log edit is part of this PR.

Prompt for agents
CONTRIBUTING.md requires each PR to record its change under the '## [Unreleased]' heading in CHANGELOG.md. This PR upgrades actions/checkout to v7 and disables credential persistence in .github/workflows/public-repo-guard.yml but adds no changelog entry. Add a short entry (e.g. under a 'Changed' or 'Security' subheading of Unreleased) describing the checkout pin bump and persist-credentials: false hardening.
Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +45 to +53
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
# Checkout defaults to persisting the job token for later steps: since v6 it
# lives in a file under $RUNNER_TEMP referenced from .git/config, no longer in
# .git/config itself. It is still a live credential in the job, and this job
# downloads a third-party binary (gitleaks, below) and runs it over the whole
# tree. Nothing here pushes -- the scan is `--no-git` over the working tree --
# so no step needs authenticated Git; drop it. (zizmor: artipacked)
persist-credentials: false

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Checkout action pin now inconsistent across workflows

This workflow is bumped to actions/checkout v7 with persist-credentials: false, while .github/workflows/_checks.yml:23,54,114 still pin v4.3.1 and .github/workflows/clang-format.yml:21 pins v6.0.3, none of which set persist-credentials: false. If the intent is repo-wide hardening (zizmor artipacked), the other workflows remain unhardened; if the intent is only to sync the vendored guard from the canonical copy, this is expected but worth a follow-up to avoid three divergent checkout pins.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

runs-on: ubuntu-latest
steps:
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Action SHA pin cannot be verified from the repo

The commit SHA 9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 is annotated as v7.0.0, but nothing in the repository lets that mapping be checked. Given this workflow is itself the pre-publication security gate and the file's header emphasizes deterministic, self-contained pinning, it is worth confirming the SHA resolves to the intended actions/checkout release tag before merge.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants