Skip to content

ci: don't persist GITHUB_TOKEN in checkout (SEC-847) - #591

Draft
Matt Sutkus (msuitcase) wants to merge 1 commit into
masterfrom
sec-842/persist-credentials
Draft

Matt Sutkus (msuitcase) wants to merge 1 commit into
masterfrom
sec-842/persist-credentials

Conversation

@msuitcase

Copy link
Copy Markdown

What

Adds persist-credentials: false to every actions/checkout step in ci.yml and release.yml.

Why

By default, actions/checkout writes the job's GITHUB_TOKEN into .git/config and leaves it there for the rest of the job. Every later step can read it, including npm install lifecycle scripts from every dependency. npm install-time malware is the main way this token gets stolen. Nothing in these workflows needs git credentials after checkout. The gh-pages deploy and the release asset upload both take the token through their own inputs.

Stack

  1. This PR: persist-credentials: false
  2. Next PR (based on this branch): least-privilege permissions:

Part of SEC-842 (org-wide rollout).

actions/checkout writes the job token into .git/config by default, where
any later step (npm install lifecycle scripts, build, tests, publish) can
read it. Nothing in these workflows needs git credentials after
checkout; the gh-pages deploy and release asset upload take the token
through their own inputs.

Refs SEC-847

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant