Skip to content

Harden GitHub Actions workflows: token permissions, SHA pinning, latest actions - #170

Open
vharseko wants to merge 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:ci-actions-permissions-pinning
Open

vharseko wants to merge 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:ci-actions-permissions-pinning

Conversation

@vharseko

Copy link
Copy Markdown
Member

Closes the 16 open medium code scanning alerts in .github/workflows (actions/missing-workflow-permissions #70–#73, #85 and actions/unpinned-tag #74–#84).

Explicit GITHUB_TOKEN permissions

Workflow / job Needs permissions
build.yml (workflow-level) checkout, artifacts, push to localhost:5000 contents: read
release.yml / release-maven mvn release:prepare pushes commits + tag, action-gh-release, wiki push contents: write
release.yml / release-docker checkout, docker/login-action to GHCR with GITHUB_TOKEN contents: read, packages: write
deploy.yml / deploy-maven checkout, wiki push (OSSRH and doc site use their own secrets/PAT) contents: write

Third-party actions pinned to commit SHAs

docker/metadata-action v6.2.0, docker/setup-qemu-action v4.4.0, docker/setup-buildx-action v4.4.1, docker/login-action v4.6.0, docker/build-push-action v7.4.0, softprops/action-gh-release v3.0.3 — each as @<sha> # vX.Y.Z. actions/* and github/codeql-action stay on major tags (first-party, not flagged by CodeQL).

Actions updated to the latest releases

  • actions/checkout v6 → v7
  • actions/setup-java v5 → v6
  • actions/cache v5 → v6
  • softprops/action-gh-release v2 → v3.0.3 (Node 24 runtime)

Release notes checked for breaking changes: checkout v7 only blocks fork-PR checkouts under pull_request_target/workflow_run (our deploy.yml job only runs for push events of the base repo); setup-java v6 and cache v6 are ESM migrations with no input changes.

.github/dependabot.yml

New: github-actions ecosystem, weekly, all action updates grouped into a single PR with labels ci + dependencies. Dependabot updates the pinned SHA and the # vX.Y.Z comment together, so the pins do not go stale.

Note for the reviewer

The permissions blocks for release.yml and deploy.yml can only be fully validated by a real release / deploy run. The wiki and doc-site steps are continue-on-error: true, so a missing permission there would not fail the workflow but would silently skip the publish — worth a glance at the logs of the first run after merge.

…st actions

- Add explicit GITHUB_TOKEN permissions to every job (read-only for
  build, contents:write for release/deploy, packages:write for the
  GHCR push) (actions/missing-workflow-permissions)
- Pin third-party actions (docker/*, softprops/action-gh-release) to
  full commit SHAs with a version comment (actions/unpinned-tag)
- Update actions/checkout to v7, actions/setup-java and actions/cache
  to v6, softprops/action-gh-release to v3.0.3
- Add .github/dependabot.yml (github-actions, weekly, grouped) so the
  pinned SHAs keep getting updated
@vharseko vharseko added dependencies Pull requests that update a dependency file security Security fixes and CVE / vulnerability updates ci Build, CI/CD, and GitHub Actions changes labels Sep 18, 2026
vharseko added a commit to vharseko/OpenIG that referenced this pull request Sep 18, 2026
vharseko added a commit to vharseko/OpenIDM that referenced this pull request Sep 18, 2026
Keeps the commit-hash-pinned third-party actions in .github/workflows up to
date: Dependabot bumps the SHA and the trailing version comment together,
grouped into one weekly PR.

Ported from OpenIdentityPlatform/OpenIG#170.
vharseko added a commit to vharseko/OpenAM that referenced this pull request Sep 18, 2026
Add "ci"/"dependencies" labels and the grouping comment to
.github/dependabot.yml, matching OpenIdentityPlatform/OpenIG#170.
vharseko added a commit to vharseko/OpenAM that referenced this pull request Sep 29, 2026
Add "ci"/"dependencies" labels and the grouping comment to
.github/dependabot.yml, matching OpenIdentityPlatform/OpenIG#170.
vharseko added a commit to vharseko/OpenAM that referenced this pull request Sep 29, 2026
Add "ci"/"dependencies" labels and the grouping comment to
.github/dependabot.yml, matching OpenIdentityPlatform/OpenIG#170.
vharseko added a commit to vharseko/OpenIDM that referenced this pull request Oct 3, 2026
Keeps the commit-hash-pinned third-party actions in .github/workflows up to
date: Dependabot bumps the SHA and the trailing version comment together,
grouped into one weekly PR.

Ported from OpenIdentityPlatform/OpenIG#170.
vharseko added a commit to vharseko/OpenIDM that referenced this pull request Oct 5, 2026
Keeps the commit-hash-pinned third-party actions in .github/workflows up to
date: Dependabot bumps the SHA and the trailing version comment together,
grouped into one weekly PR.

Ported from OpenIdentityPlatform/OpenIG#170.
vharseko added a commit to OpenIdentityPlatform/OpenIDM that referenced this pull request Oct 6, 2026
* Harden GitHub workflows and SMTP STARTTLS trust

- Set an explicit read-only GITHUB_TOKEN permissions block on the build,
  deploy and release workflows, elevating only the jobs that need it
  (wiki/docs push and release tag: contents:write; ghcr push: packages:write)
- Pin the third-party docker/* and softprops/action-gh-release actions to
  commit SHAs
- EmailClient: stop trusting every SMTP server certificate over STARTTLS;
  validation is now the default, with opt-in starttls.trustedHosts /
  starttls.trustAll settings (documented)

Resolves CodeQL alerts #711-#716, #718-#738, #920, #921 (actions) and #22
(java/insecure-smtp-ssl).

* Add .github/dependabot.yml for the SHA-pinned actions

Keeps the commit-hash-pinned third-party actions in .github/workflows up to
date: Dependabot bumps the SHA and the trailing version comment together,
grouped into one weekly PR.

Ported from OpenIdentityPlatform/OpenIG#170.

* Address review on STARTTLS trust: host check, trustedHosts, Admin UI

- Validate the SMTP certificate's host name by default
  (mail.smtp.ssl.checkserveridentity=true); JavaMail 1.4.7 leaves it off
- Exclude jakarta.mail from the email bundle's classpath: compiling against
  its com.sun.mail.util made the bundle import MailSSLSocketFactory from
  jakarta.mail, which javax.mail's SocketFetcher does not recognise, so
  starttls.trustedHosts trusted every host
- Warn when starttls.trustedHosts does not contain the SMTP host
- Admin UI: keep starttls.trustedHosts/trustAll when saving the Email form
- Tests: host check, trustAll precedence, socket factory origin
- Docs: host match, exact trustedHosts entry, trustAll precedence

* Embed javax.mail in the email bundle and enable current TLS for STARTTLS

The com.sun.mail.util [1.4,2) import from the previous commit left
openidm-external-email unresolved, so OpenIDM never reached "ready" in CI:
javax.mail 1.4.7 imports its own com.sun.mail.* packages with no upper
bound, Felix wires them to jakarta.mail 2.0.2 and drops the 1.4.7 exports.
The same wiring already broke mail on master, where MimeMessage fails with
NoSuchMethodError on com.sun.mail.util.PropUtil.

- Embed javax.mail 1.4.7 in the bundle so Session, SMTPTransport,
  SocketFetcher and MailSSLSocketFactory come from one jar, and point the
  context class loader at the bundle while JavaMail loads its providers.
- Set mail.smtp.ssl.protocols to the JVM defaults when STARTTLS is on.
  Without it JavaMail 1.4.7 enables only TLSv1, which current JDKs
  disable, so no STARTTLS handshake could succeed.

* Address review round 2 on STARTTLS trust: IP SAN note and tests

- chap-mail.adoc: on Java 17+ the host is matched only against DNS SANs
  (or the CN), so a relay addressed by IP is rejected even with an IP SAN
- EmailClientTest: replace withoutStartTlsNoSocketFactoryIsConfigured with
  trustSettingsApplyOnlyWithStartTls, which fails if the trust settings
  are applied outside STARTTLS
- EmailConfigViewTest: pin that saving Settings > Email keeps
  starttls.trustedHosts and starttls.trustAll
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Build, CI/CD, and GitHub Actions changes dependencies Pull requests that update a dependency file security Security fixes and CVE / vulnerability updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant