From 0bd1e3c196a9d077eb33382f00628ba493257e9e Mon Sep 17 00:00:00 2001 From: justin Date: Fri, 25 Sep 2026 20:22:45 -0600 Subject: [PATCH 1/5] fix(ci): rely on pull request author check in dependabot auto-merge --- .github/workflows/auto-merge.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index fb16d59562..17c779e761 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -13,8 +13,9 @@ jobs: dependabot: runs-on: blacksmith-4vcpu-ubuntu-2404 timeout-minutes: 45 + # The pull request author's login is authoritative for this check; + # github.actor would be spoofable and adds nothing on top of it. if: >- - github.actor == 'dependabot[bot]' && github.event.pull_request.user.login == 'dependabot[bot]' && github.event.pull_request.base.ref == 'main' && github.event.pull_request.head.repo.full_name == github.repository From 4c8dda53c55ebc360c68b109771ead175f7e9e6e Mon Sep 17 00:00:00 2001 From: justin Date: Fri, 25 Sep 2026 20:22:46 -0600 Subject: [PATCH 2/5] fix(ci): declare and pass required secrets to image build workflow --- .github/workflows/build-images.yml | 7 +++++++ .github/workflows/docker.yml | 5 ++++- .github/workflows/nightly.yml | 6 +++++- .github/workflows/release.yml | 7 ++++++- 4 files changed, 22 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build-images.yml b/.github/workflows/build-images.yml index fa3400de08..5cdbbf1736 100644 --- a/.github/workflows/build-images.yml +++ b/.github/workflows/build-images.yml @@ -21,6 +21,13 @@ on: required: false type: string default: linux/amd64,linux/arm64 + secrets: + # GHCR login token with package push rights. + GH_PACKAGE_TOKEN: + required: true + # Source-map upload token; only the web image build uses it. + SENTRY_AUTH_TOKEN: + required: false jobs: build: diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index cbb32c921b..8e4f6cd06a 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -19,8 +19,11 @@ jobs: permissions: contents: read packages: write + uses: ./.github/workflows/build-images.yml - secrets: inherit + secrets: + GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} + SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} with: source_mode: released version: ${{ inputs.version }} diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index e017c5621c..2cfeeb8b9e 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -187,6 +187,7 @@ jobs: verify: name: Verify nightly build if: ${{ github.ref == format('refs/heads/{0}', github.event.repository.default_branch) }} + uses: ./.github/workflows/ci.yml publish-images: @@ -196,8 +197,11 @@ jobs: permissions: contents: read packages: write + uses: ./.github/workflows/build-images.yml - secrets: inherit + secrets: + GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} + SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} with: source_mode: nightly tags: | diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f40d9cad83..189bc79fe4 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -124,8 +124,11 @@ jobs: permissions: contents: read packages: write + uses: ./.github/workflows/build-images.yml - secrets: inherit + secrets: + GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} + SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} with: source_mode: planned version: ${{ needs.plan.outputs.version }} @@ -137,6 +140,7 @@ jobs: if: ${{ !inputs.dry_run && needs.plan.outputs.version != '' }} permissions: contents: read + uses: ./.github/workflows/helm-validate.yml release: @@ -233,6 +237,7 @@ jobs: permissions: contents: read packages: write + uses: ./.github/workflows/helm-chart.yml with: version: ${{ needs.plan.outputs.version }} From 89b5ed91e17718d69aa63b3dd7a7f4ef490f6d7d Mon Sep 17 00:00:00 2001 From: justin Date: Fri, 25 Sep 2026 20:22:46 -0600 Subject: [PATCH 3/5] fix(ci): disable setup-node caching in publish workflows --- .github/workflows/publish-mcp.yml | 4 +++- .github/workflows/publish-planka-import.yml | 4 +++- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/.github/workflows/publish-mcp.yml b/.github/workflows/publish-mcp.yml index 513c0811a5..3824128a17 100644 --- a/.github/workflows/publish-mcp.yml +++ b/.github/workflows/publish-mcp.yml @@ -51,7 +51,9 @@ jobs: uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: 24.19.0 - cache: pnpm + # Publish workflows must not read cache content that a pull + # request could have poisoned (zizmor cache-poisoning). + package-manager-cache: false - name: Install dependencies run: pnpm install --frozen-lockfile diff --git a/.github/workflows/publish-planka-import.yml b/.github/workflows/publish-planka-import.yml index 7cd2f46f4c..0496dfb6cf 100644 --- a/.github/workflows/publish-planka-import.yml +++ b/.github/workflows/publish-planka-import.yml @@ -50,7 +50,9 @@ jobs: uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: 24 - cache: pnpm + # Publish workflows must not read cache content that a pull + # request could have poisoned (zizmor cache-poisoning). + package-manager-cache: false - name: Install dependencies run: pnpm install --frozen-lockfile From eac0a5e0df6d6f115a69248779110c41d54eb1d4 Mon Sep 17 00:00:00 2001 From: justin Date: Fri, 25 Sep 2026 20:22:47 -0600 Subject: [PATCH 4/5] chore(ci): document pull_request_target usage in bot workflows --- .github/workflows/auto-assign.yml | 4 +++- .github/workflows/auto-merge.yml | 3 +++ .github/workflows/pr-size-labeler.yml | 2 ++ 3 files changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/auto-assign.yml b/.github/workflows/auto-assign.yml index b50f599a68..065f01c100 100644 --- a/.github/workflows/auto-assign.yml +++ b/.github/workflows/auto-assign.yml @@ -2,7 +2,9 @@ name: Auto Assign on: issues: types: [opened] - pull_request_target: + # zizmor: ignore[dangerous-triggers] Assigns pull requests via the API + # only; never checks out or executes untrusted code. + pull_request_target: types: [opened] jobs: run: diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 17c779e761..75fdb17186 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -2,6 +2,9 @@ name: Dependabot Auto-Merge # Never check out or execute pull-request content in this privileged workflow. on: + # zizmor: ignore[dangerous-triggers] Never checks out or executes pull + # request content; merges via the GitHub API only after required checks pass + # and the head commit is pinned. pull_request_target: types: [opened, synchronize, reopened, ready_for_review] diff --git a/.github/workflows/pr-size-labeler.yml b/.github/workflows/pr-size-labeler.yml index 6c17c38364..0cb572c98a 100644 --- a/.github/workflows/pr-size-labeler.yml +++ b/.github/workflows/pr-size-labeler.yml @@ -1,6 +1,8 @@ name: PR Size Labeler on: + # zizmor: ignore[dangerous-triggers] Labels pull requests via the API; + # checks out only the trusted base-branch size configuration. pull_request_target: types: [opened, synchronize, reopened] From fd91d25754644ffe4eaf734761ca2606e5eb84a3 Mon Sep 17 00:00:00 2001 From: justin Date: Fri, 25 Sep 2026 20:22:47 -0600 Subject: [PATCH 5/5] chore(ci): document self-repository uses until actionlint supports $/ --- .github/workflows/docker.yml | 2 +- .github/workflows/helm-chart.yml | 3 ++- .github/workflows/nightly.yml | 4 ++-- .github/workflows/release.yml | 6 +++--- .github/workflows/ui-review.yml | 3 ++- 5 files changed, 10 insertions(+), 8 deletions(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 8e4f6cd06a..4a968e6f45 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -20,7 +20,7 @@ jobs: contents: read packages: write - uses: ./.github/workflows/build-images.yml + uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported secrets: GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} diff --git a/.github/workflows/helm-chart.yml b/.github/workflows/helm-chart.yml index 3e383718ae..e54a12d532 100644 --- a/.github/workflows/helm-chart.yml +++ b/.github/workflows/helm-chart.yml @@ -29,7 +29,8 @@ jobs: validate: permissions: contents: read - uses: ./.github/workflows/helm-validate.yml + + uses: ./.github/workflows/helm-validate.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported publish: if: github.ref == 'refs/heads/main' && inputs.version != '' diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index 2cfeeb8b9e..a9e21f81a9 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -188,7 +188,7 @@ jobs: name: Verify nightly build if: ${{ github.ref == format('refs/heads/{0}', github.event.repository.default_branch) }} - uses: ./.github/workflows/ci.yml + uses: ./.github/workflows/ci.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported publish-images: name: Publish nightly images @@ -198,7 +198,7 @@ jobs: contents: read packages: write - uses: ./.github/workflows/build-images.yml + uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported secrets: GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 189bc79fe4..bc5590c8e3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -125,7 +125,7 @@ jobs: contents: read packages: write - uses: ./.github/workflows/build-images.yml + uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported secrets: GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }} SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} @@ -141,7 +141,7 @@ jobs: permissions: contents: read - uses: ./.github/workflows/helm-validate.yml + uses: ./.github/workflows/helm-validate.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported release: name: Release @@ -238,6 +238,6 @@ jobs: contents: read packages: write - uses: ./.github/workflows/helm-chart.yml + uses: ./.github/workflows/helm-chart.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported with: version: ${{ needs.plan.outputs.version }} diff --git a/.github/workflows/ui-review.yml b/.github/workflows/ui-review.yml index 826cf00de1..c962fefc12 100644 --- a/.github/workflows/ui-review.yml +++ b/.github/workflows/ui-review.yml @@ -54,7 +54,8 @@ jobs: concurrency: group: peekareq-${{ needs.authorize.outputs.pr }} cancel-in-progress: true - uses: ./.github/workflows/ui-review-run.yml + + uses: ./.github/workflows/ui-review-run.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported with: pr: ${{ needs.authorize.outputs.pr }} model: ${{ needs.authorize.outputs.model }}