Skip to content

fix(ci): zizmor findings - #1791

Merged
randoneering merged 5 commits into
mainfrom
fix/ci-zizmor-findings
Sep 26, 2026
Merged

randoneering merged 5 commits into
mainfrom
fix/ci-zizmor-findings

Conversation

@randoneering

@randoneering randoneering commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Description

Just cleanup work after implementing zizmor:

  • dropped the spoofable actor check in the dependabot auto-merge
  • declared and passed only the two secrets the image build actually needs
  • turned off the dependency cache in publish workflows.

Related Issue(s)

Fixes #

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Refactoring (no functional changes)
  • Performance improvement
  • Test addition or update
  • Other (please describe): CI Fix

How Has This Been Tested?

  • Unit tests
  • Integration tests
  • Manual testing
  • Other (please describe):

Screenshots (if applicable)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I understand and take responsibility for every change, and I wrote this pull request description in my own words
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged and published

Additional Notes


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Harden GitHub Actions workflows against zizmor findings

🐞 Bug fix ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Resolves zizmor findings across privileged, reusable, and publishing GitHub Actions workflows.
• Restricts image builds to explicitly declared package and Sentry secrets.
• Disables publish-time dependency caches and documents reviewed security exceptions.
Diagram

graph TD
  A["PR events"] -->|"trusted metadata"| B["API automation"]
  C["Image workflows"] -->|"named secrets"| D["Reusable build"] --> E["GHCR and Sentry"]
  F["Publish workflows"] -->|"cache disabled"| G["Node setup"] --> H["Package registries"]
Loading
High-Level Assessment

The PR uses the appropriate targeted remediations. Retaining pull_request_target is necessary for privileged API operations and is safe here because untrusted code is not executed; explicit secret mappings reduce exposure compared with secrets: inherit; and disabling publish-time caches is safer than maintaining a complex trusted-cache scheme. Switching event types or introducing custom cache isolation would add complexity without a clear benefit.

Files changed (11) +48 / -15

Bug fix (3) +11 / -3
auto-merge.ymlRemove the spoofable actor check from Dependabot merging +5/-1

Remove the spoofable actor check from Dependabot merging

• Relies on the pull request author's login as the authoritative Dependabot identity check. Documents why the privileged trigger is safe and why github.actor provides no additional protection.

.github/workflows/auto-merge.yml

publish-mcp.ymlDisable dependency caching for MCP publishing +3/-1

Disable dependency caching for MCP publishing

• Disables setup-node package-manager caching so the privileged publication job cannot restore cache content potentially poisoned by pull requests.

.github/workflows/publish-mcp.yml

publish-planka-import.ymlDisable dependency caching for importer publishing +3/-1

Disable dependency caching for importer publishing

• Disables setup-node package-manager caching to prevent the publication job from consuming potentially poisoned pull request cache entries.

.github/workflows/publish-planka-import.yml

Other (8) +37 / -12
auto-assign.ymlDocument the privileged auto-assignment trigger +3/-1

Document the privileged auto-assignment trigger

• Adds a zizmor suppression explaining that pull_request_target is limited to API-based assignment and never executes untrusted pull request code.

.github/workflows/auto-assign.yml

build-images.ymlDeclare the reusable image workflow secret contract +7/-0

Declare the reusable image workflow secret contract

• Declares the required GHCR package token and optional Sentry source-map token as workflow_call secrets.

.github/workflows/build-images.yml

docker.ymlPass only required secrets to image builds +5/-2

Pass only required secrets to image builds

• Replaces inherited secrets with explicit GH_PACKAGE_TOKEN and SENTRY_AUTH_TOKEN mappings. Documents the temporary self-repository zizmor suppression.

.github/workflows/docker.yml

helm-chart.ymlDocument the local Helm validation workflow reference +2/-1

Document the local Helm validation workflow reference

• Adds a targeted self-repository suppression for the reusable Helm validation workflow until the pinned actionlint version supports the preferred syntax.

.github/workflows/helm-chart.yml

nightly.ymlRestrict nightly image secrets and document local workflow calls +7/-3

Restrict nightly image secrets and document local workflow calls

• Passes only the package and Sentry tokens into the reusable image build. Adds targeted self-repository suppressions to nightly CI and image workflow references.

.github/workflows/nightly.yml

pr-size-labeler.ymlDocument the privileged PR labeling trigger +2/-0

Document the privileged PR labeling trigger

• Explains that the labeler uses pull_request_target only for API labeling and checks out trusted base-branch configuration.

.github/workflows/pr-size-labeler.yml

release.ymlRestrict release secrets and document reusable workflow references +9/-4

Restrict release secrets and document reusable workflow references

• Replaces inherited image-build secrets with explicit package and Sentry token mappings. Adds targeted self-repository suppressions for image, Helm validation, and chart workflow calls.

.github/workflows/release.yml

ui-review.ymlDocument the local UI review workflow reference +2/-1

Document the local UI review workflow reference

• Adds a targeted self-repository suppression for the reusable UI review workflow until the pinned actionlint parser supports the preferred syntax.

.github/workflows/ui-review.yml

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can type 'qodo, fix this' on a finding and the fix lands right on your PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@randoneering
randoneering merged commit db66386 into main Sep 26, 2026
29 of 30 checks passed
@randoneering
randoneering deleted the fix/ci-zizmor-findings branch September 26, 2026 02:34
zaralX pushed a commit to zaralX/kaneo that referenced this pull request Sep 26, 2026
### Features

- gitlab integration: usekaneo#1727
- **tasks:** show subtask progress on cards and list rows: usekaneo#1703
- added project backgrounds: usekaneo#1654
- multiselect for customfield: usekaneo#1735
- **ci:** discord actions webhook: usekaneo#1792
- **ci:** adding zizmor: usekaneo#1790
- **project:** move a project to another workspace: usekaneo#1525
- duplicate a task from the card context menu: usekaneo#1609
- allow manual external resource links: usekaneo#1661
- **ci:** trufflehog implementation: usekaneo#1787
- **task:** let images be resized in the task description: usekaneo#1529
- **web:** add a change-password screen under account settings: usekaneo#1719
- **auth:** add password recovery from the login screen: usekaneo#1773
- add instance user administration panel: usekaneo#1400
- **calendar:** add label-filtered project calendar feeds: usekaneo#1763

### Bug Fixes

- **security:** close permission and integration gaps: usekaneo#1802
- **project:** secure integrations across workspace moves: usekaneo#1801
- **editor:** preserve formatting when pasting Markdown: usekaneo#1797
- **auth:** report invitation email delivery failures: usekaneo#1798
- **gitea:** verify saved repository connections: usekaneo#1796
- **mcp:** keep OAuth requests valid outside UTC: usekaneo#1795
- **i18n:** translate calendar in remaining locales: [1d61ceb](usekaneo@1d61ceb)
- **ci:** zizmor findings: usekaneo#1791
- **integrations:** resolve PRs through linked issue identities: usekaneo#1739
- **auth:** prevent repeated 401s for pending invitations after session expiry: usekaneo#1715
- **auth:** gate sign-in emails to deliverable addresses: usekaneo#1758
- **web:** preserve image uploads across editor recreation: usekaneo#1738
- **reminders:** calculate deadlines from the end of the due day: usekaneo#1762
- **mcp:** support whoami with API keys: usekaneo#1748
- **web:** respect DISABLE_WORKSPACE_CREATION on the onboarding screen: usekaneo#1744
- **backlog:** prevent task remounts during list interactions: usekaneo#1734
- **auth:** prevent role changes from removing the last admin: usekaneo#1733
- **npm:** fixing GHSA-2xp9-vwfh-vxw4: usekaneo#1777
- **web:** guard tiptap setHardBreak against invalid-content schema error: [be3ffb5](usekaneo@be3ffb5)
- **i18n:** prevent locale module crash on stale dynamic import: usekaneo#1775
- **site:** improve search metadata and product discovery: [121183e](usekaneo@121183e)

### Performance Improvements

- **project:** stop returning tasks with project details: usekaneo#1800

### Documentation

- update contributors and sponsors: [fa07f10](usekaneo@fa07f10)
- **site:** add Blacksmith partner badge to site and README: [08a93b8](usekaneo@08a93b8)
- update contributors and sponsors: [8432a45](usekaneo@8432a45)

### Credits

Huge thanks to @tinsever, @zaralX, @TymekV, @MonsPropre, @randoneering, @rdlugs, @tbringuier, @mohiuddin000, @shiminshen, @yavilavi, @thejdubb02, @yigit-serin, @OmG3r, and @zerodarkzone for helping!
github-actions Bot added a commit to capital-shield/kaneo that referenced this pull request Oct 3, 2026
### Features

- **web:** redesign settings: usekaneo#1905
- **site:** link community projects from resources: [69ba99d](69ba99d)
- **site:** add a community projects page: [961c309](961c309)
- **site:** sync product preview with home, inbox and my tasks: [30ba825](30ba825)
- missing french translation: usekaneo#1903
- add short task links like /acme/task/KAN-12: usekaneo#1891
- **web:** add home, inbox and my tasks pages: usekaneo#1898
- **web:** wire the task copy shortcuts: usekaneo#1897
- **web:** move task delete into the action group: usekaneo#1896
- **site:** add guides and retarget alternatives: [58f6d47](58f6d47)
- **web:** track the cloud signup funnel: [abacad7](abacad7)
- **docker:** support file-backed secrets for container deployments: usekaneo#1853
- sort labels alphabetically: usekaneo#1856
- **web:** select task ranges with shift-click: usekaneo#1838
- clickable task PR list, task link matching, and reopen completed tasks for new work: usekaneo#1864
- **mcp:** get tasks by ticket ID: usekaneo#1839
- **web:** guide cloud users through invites and plan choice during onboarding: usekaneo#1840
- rank new issue priority with Jev: [594e016](594e016)
- **web:** cloud sign-up and onboarding layout: usekaneo#1832
- gitlab integration: usekaneo#1727
- **tasks:** show subtask progress on cards and list rows: usekaneo#1703
- added project backgrounds: usekaneo#1654
- multiselect for customfield: usekaneo#1735
- **ci:** discord actions webhook: usekaneo#1792
- **ci:** adding zizmor: usekaneo#1790
- **project:** move a project to another workspace: usekaneo#1525
- duplicate a task from the card context menu: usekaneo#1609
- allow manual external resource links: usekaneo#1661
- **ci:** trufflehog implementation: usekaneo#1787
- **task:** let images be resized in the task description: usekaneo#1529
- **web:** add a change-password screen under account settings: usekaneo#1719
- **auth:** add password recovery from the login screen: usekaneo#1773
- add instance user administration panel: usekaneo#1400
- **site:** bring product preview up to date with current app: [dd855f7](dd855f7)
- **site:** refresh marketing site and interactive product previews: [90aec99](90aec99)
- **calendar:** add label-filtered project calendar feeds: usekaneo#1763

### Bug Fixes

- **web:** send subscription revenue as a property: [445b735](445b735)
- **site:** list GitLab with the git integrations: [3c01517](3c01517)
- **site:** serve favicon.ico: [e7ef050](e7ef050)
- **docs:** load the docs font from its real path: [22c7a02](22c7a02)
- **tasks:** make bulk status changes atomic: usekaneo#1873
- **integrations:** preserve rapid legitimate edits: usekaneo#1874
- **integrations:** enforce current task ownership: usekaneo#1867
- **ws:** revoke removed workspace members: usekaneo#1865
- **migrations:** record workflow migration completion: usekaneo#1872
- **auth:** enforce api key quotas and rate limits: usekaneo#1869
- **mcp:** share tools and support workspace label deletion: usekaneo#1871
- **reminders:** persist notification and claim atomically: usekaneo#1870
- **integrations:** require task update permission for imports: usekaneo#1868
- **ci:** publish npm provenance on GitHub-hosted runners: [50779a4](50779a4)
- **gitea:** reject saved tokens for changed servers: usekaneo#1866
- **ci:** pass the GitHub token to AgentScan: usekaneo#1862
- **ci:** resolve nightly warnings and errors: usekaneo#1858
- **api:** make legacy MCP HTTP requests replica independent: usekaneo#1850
- **docker:** disable wget proxy for loopback health checks: usekaneo#1841
- **billing:** resize Creem seats by subscription item id: usekaneo#1836
- **gitea:** prevent outbound comment echoes: usekaneo#1834
- **deps:** migrate Sentry SDKs together to v11 (usekaneo#1826): usekaneo#1826
- **ci:** grant nightly reusable CI scan permission: [0216067](0216067)
- **board:** allow column moves while sorting by task number: usekaneo#1816
- **auth:** backfill instance admin on legacy installations: [b7c6aee](b7c6aee)
- **admin:** harden the user administration panel: usekaneo#1805
- **admin:** allow updating your own email without changing role: [3d57439](3d57439)
- **security:** close permission and integration gaps: usekaneo#1802
- **project:** secure integrations across workspace moves: usekaneo#1801
- **editor:** preserve formatting when pasting Markdown: usekaneo#1797
- **auth:** report invitation email delivery failures: usekaneo#1798
- **gitea:** verify saved repository connections: usekaneo#1796
- **mcp:** keep OAuth requests valid outside UTC: usekaneo#1795
- **i18n:** translate calendar in remaining locales: [1d61ceb](1d61ceb)
- **ci:** zizmor findings: usekaneo#1791
- **integrations:** resolve PRs through linked issue identities: usekaneo#1739
- **auth:** prevent repeated 401s for pending invitations after session expiry: usekaneo#1715
- **auth:** gate sign-in emails to deliverable addresses: usekaneo#1758
- **web:** preserve image uploads across editor recreation: usekaneo#1738
- **reminders:** calculate deadlines from the end of the due day: usekaneo#1762
- **mcp:** support whoami with API keys: usekaneo#1748
- **web:** respect DISABLE_WORKSPACE_CREATION on the onboarding screen: usekaneo#1744
- **backlog:** prevent task remounts during list interactions: usekaneo#1734
- **auth:** prevent role changes from removing the last admin: usekaneo#1733
- **npm:** fixing GHSA-2xp9-vwfh-vxw4: usekaneo#1777
- **web:** guard tiptap setHardBreak against invalid-content schema error: [be3ffb5](be3ffb5)
- **i18n:** prevent locale module crash on stale dynamic import: usekaneo#1775
- **site:** improve search metadata and product discovery: [121183e](121183e)
- **web:** allow non-root runtime configuration writes: usekaneo#1767
- **site:** poof away preview cursor on interaction: [08dcaee](08dcaee)
- **nginx:** allow larger OAuth session headers: usekaneo#1761
- **deps:** resolve open dependabot advisories: [b8432a0](b8432a0)
- **web:** preserve comment markdown spacing: usekaneo#1521

### Performance Improvements

- **project:** stop returning tasks with project details: usekaneo#1800

### Documentation

- update sponsors: [1c51887](1c51887)
- add AI Policy badge to README: [011c8ee](011c8ee)
- update sponsors: [e45c8ac](e45c8ac)
- assign issue types from templates: [4725cfa](4725cfa)
- simplify issue and pull request templates: [cb6ce20](cb6ce20)
- adopt Human Voice AI contribution policy: [b090123](b090123)
- overhaul agents.md: [4d619aa](4d619aa)
- **readme:** highlight cloud and current features: usekaneo#1831
- update contributors and sponsors: [c200d70](c200d70)
- rebuild guides around current Kaneo workflows: usekaneo#1814
- acknowledge BrowserStack testing: [e389a68](e389a68)
- update contributors and sponsors: [fa07f10](fa07f10)
- **site:** add Blacksmith partner badge to site and README: [08a93b8](08a93b8)
- update contributors and sponsors: [8432a45](8432a45)
- **site:** refresh press kit with product screenshots: [3470b0a](3470b0a)
- update blog comparisons for current Kaneo features: [b97bf7d](b97bf7d)
- update contributors and sponsors: [6c7001c](6c7001c)

### Credits

Huge thanks to @tinsever, @MonsPropre, @andrejsshell, @tuttucodes, @druwan, @randoneering, @mazzz1y, @zaralX, @TymekV, @rdlugs, @tbringuier, @mohiuddin000, @shiminshen, @yavilavi, @thejdubb02, @yigit-serin, @OmG3r, and @zerodarkzone for helping!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant