Skip to content

fix(ci): don't persist credentials in actions/checkout - #991

Merged
saghen merged 1 commit into
mainfrom
sb/push-kznstxlpqxrs
Jan 11, 2025
Merged

fix(ci): don't persist credentials in actions/checkout#991
saghen merged 1 commit into
mainfrom
sb/push-kznstxlpqxrs

Conversation

@stefanboca

Copy link
Copy Markdown
Collaborator

Identified with zizmor. It's also possible to run zizmore in ci, but I didn't implement this because it requires a GITHUB_TOKEN secret.

Identified with [zizmor](https://woodruffw.github.io/zizmor/).
It's also possible to [run zizmore in ci](https://woodruffw.github.io/zizmor/usage/#use-in-github-actions),
but I didn't implement this because it requires a GITHUB_TOKEN secret.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying blink-cmp-main with  Cloudflare Pages  Cloudflare Pages

Latest commit: 2ff9d4f
Status:🚫  Build failed.

View logs

@stefanboca

Copy link
Copy Markdown
Collaborator Author

This is, assuming that the release action doesn't require persist-credentials: true. If it does, it should be explicitly set.

@saghen

saghen commented Jan 11, 2025

Copy link
Copy Markdown
Owner

It only has contents: read permission, does it matter?

@stefanboca

stefanboca commented Jan 11, 2025

Copy link
Copy Markdown
Collaborator Author

The docs state

When the permissions key is used, all unspecified permissions are set to no access, with the exception of the metadata scope, which always gets read access.

so apparently not. Although IMHO, I don't see how it can hurt :)

Please feel free to close this if you think it isn't necessary though.

@saghen
saghen merged commit 1ddd01b into main Jan 11, 2025
@saghen

saghen commented Jan 11, 2025

Copy link
Copy Markdown
Owner

I don't see how it can hurt

Yup good point, thanks!

@stefanboca
stefanboca deleted the sb/push-kznstxlpqxrs branch January 12, 2025 03:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants