diff --git a/.github/workflows/auto-assign.yml b/.github/workflows/auto-assign.yml index b50f599a68..065f01c100 100644 --- a/.github/workflows/auto-assign.yml +++ b/.github/workflows/auto-assign.yml @@ -2,7 +2,9 @@ name: Auto Assign on: issues: types: [opened] - pull_request_target: + # zizmor: ignore[dangerous-triggers] Assigns pull requests via the API + # only; never checks out or executes untrusted code. + pull_request_target: types: [opened] jobs: run: diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index fb16d59562..75fdb17186 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -2,6 +2,9 @@ name: Dependabot Auto-Merge # Never check out or execute pull-request content in this privileged workflow. on: + # zizmor: ignore[dangerous-triggers] Never checks out or executes pull + # request content; merges via the GitHub API only after required checks pass + # and the head commit is pinned. pull_request_target: types: [opened, synchronize, reopened, ready_for_review] @@ -13,8 +16,9 @@ jobs: dependabot: runs-on: blacksmith-4vcpu-ubuntu-2404 timeout-minutes: 45 + # The pull request author's login is authoritative for this check; + # github.actor would be spoofable and adds nothing on top of it. if: >- - github.actor == 'dependabot[bot]' && github.event.pull_request.user.login == 'dependabot[bot]' && github.event.pull_request.base.ref == 'main' && github.event.pull_request.head.repo.full_name == github.repository diff --git a/.github/workflows/build-images.yml b/.github/workflows/build-images.yml index fa3400de08..5cdbbf1736 100644 --- a/.github/workflows/build-images.yml +++ b/.github/workflows/build-images.yml @@ -21,6 +21,13 @@ on: required: false type: string default: linux/amd64,linux/arm64 + secrets: + # GHCR login token with package push rights. + GH_PACKAGE_TOKEN: + required: true + # Source-map upload token; only the web image build uses it. + SENTRY_AUTH_TOKEN: + required: false jobs: build: diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index cbb32c921b..4a968e6f45 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -19,8 +19,11 @@ jobs: permissions: contents: read packages: write - uses: ./.github/workflows/build-images.yml - secrets: inherit + + uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported + secrets: + GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} + SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} with: source_mode: released version: ${{ inputs.version }} diff --git a/.github/workflows/helm-chart.yml b/.github/workflows/helm-chart.yml index 3e383718ae..e54a12d532 100644 --- a/.github/workflows/helm-chart.yml +++ b/.github/workflows/helm-chart.yml @@ -29,7 +29,8 @@ jobs: validate: permissions: contents: read - uses: ./.github/workflows/helm-validate.yml + + uses: ./.github/workflows/helm-validate.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported publish: if: github.ref == 'refs/heads/main' && inputs.version != '' diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index e017c5621c..a9e21f81a9 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -187,7 +187,8 @@ jobs: verify: name: Verify nightly build if: ${{ github.ref == format('refs/heads/{0}', github.event.repository.default_branch) }} - uses: ./.github/workflows/ci.yml + + uses: ./.github/workflows/ci.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported publish-images: name: Publish nightly images @@ -196,8 +197,11 @@ jobs: permissions: contents: read packages: write - uses: ./.github/workflows/build-images.yml - secrets: inherit + + uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported + secrets: + GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} + SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} with: source_mode: nightly tags: | diff --git a/.github/workflows/pr-size-labeler.yml b/.github/workflows/pr-size-labeler.yml index 6c17c38364..0cb572c98a 100644 --- a/.github/workflows/pr-size-labeler.yml +++ b/.github/workflows/pr-size-labeler.yml @@ -1,6 +1,8 @@ name: PR Size Labeler on: + # zizmor: ignore[dangerous-triggers] Labels pull requests via the API; + # checks out only the trusted base-branch size configuration. pull_request_target: types: [opened, synchronize, reopened] diff --git a/.github/workflows/publish-mcp.yml b/.github/workflows/publish-mcp.yml index 513c0811a5..3824128a17 100644 --- a/.github/workflows/publish-mcp.yml +++ b/.github/workflows/publish-mcp.yml @@ -51,7 +51,9 @@ jobs: uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: 24.19.0 - cache: pnpm + # Publish workflows must not read cache content that a pull + # request could have poisoned (zizmor cache-poisoning). + package-manager-cache: false - name: Install dependencies run: pnpm install --frozen-lockfile diff --git a/.github/workflows/publish-planka-import.yml b/.github/workflows/publish-planka-import.yml index 7cd2f46f4c..0496dfb6cf 100644 --- a/.github/workflows/publish-planka-import.yml +++ b/.github/workflows/publish-planka-import.yml @@ -50,7 +50,9 @@ jobs: uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: 24 - cache: pnpm + # Publish workflows must not read cache content that a pull + # request could have poisoned (zizmor cache-poisoning). + package-manager-cache: false - name: Install dependencies run: pnpm install --frozen-lockfile diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f40d9cad83..bc5590c8e3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -124,8 +124,11 @@ jobs: permissions: contents: read packages: write - uses: ./.github/workflows/build-images.yml - secrets: inherit + + uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported + secrets: + GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} + SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} with: source_mode: planned version: ${{ needs.plan.outputs.version }} @@ -137,7 +140,8 @@ jobs: if: ${{ !inputs.dry_run && needs.plan.outputs.version != '' }} permissions: contents: read - uses: ./.github/workflows/helm-validate.yml + + uses: ./.github/workflows/helm-validate.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported release: name: Release @@ -233,6 +237,7 @@ jobs: permissions: contents: read packages: write - uses: ./.github/workflows/helm-chart.yml + + uses: ./.github/workflows/helm-chart.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported with: version: ${{ needs.plan.outputs.version }} diff --git a/.github/workflows/ui-review.yml b/.github/workflows/ui-review.yml index 826cf00de1..c962fefc12 100644 --- a/.github/workflows/ui-review.yml +++ b/.github/workflows/ui-review.yml @@ -54,7 +54,8 @@ jobs: concurrency: group: peekareq-${{ needs.authorize.outputs.pr }} cancel-in-progress: true - uses: ./.github/workflows/ui-review-run.yml + + uses: ./.github/workflows/ui-review-run.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported with: pr: ${{ needs.authorize.outputs.pr }} model: ${{ needs.authorize.outputs.model }}