Repository navigation
Conversation
…st actions - Add explicit GITHUB_TOKEN permissions to every job (read-only for build, contents:write for release/deploy, packages:write for the GHCR push) (actions/missing-workflow-permissions) - Pin third-party actions (docker/*, softprops/action-gh-release) to full commit SHAs with a version comment (actions/unpinned-tag) - Update actions/checkout to v7, actions/setup-java and actions/cache to v6, softprops/action-gh-release to v3.0.3 - Add .github/dependabot.yml (github-actions, weekly, grouped) so the pinned SHAs keep getting updated
vharseko
added a commit
to vharseko/OpenIG
that referenced
this pull request
Sep 18, 2026
Same file as in OpenIdentityPlatform#170; whichever PR lands first brings it in.
vharseko
added a commit
to vharseko/OpenIDM
that referenced
this pull request
Sep 18, 2026
Keeps the commit-hash-pinned third-party actions in .github/workflows up to date: Dependabot bumps the SHA and the trailing version comment together, grouped into one weekly PR. Ported from OpenIdentityPlatform/OpenIG#170.
7 of 9 tasks
vharseko
added a commit
to vharseko/OpenAM
that referenced
this pull request
Sep 18, 2026
Add "ci"/"dependencies" labels and the grouping comment to .github/dependabot.yml, matching OpenIdentityPlatform/OpenIG#170.
vharseko
added a commit
to vharseko/OpenAM
that referenced
this pull request
Sep 29, 2026
Add "ci"/"dependencies" labels and the grouping comment to .github/dependabot.yml, matching OpenIdentityPlatform/OpenIG#170.
vharseko
added a commit
to vharseko/OpenAM
that referenced
this pull request
Sep 29, 2026
Add "ci"/"dependencies" labels and the grouping comment to .github/dependabot.yml, matching OpenIdentityPlatform/OpenIG#170.
vharseko
added a commit
to vharseko/OpenIDM
that referenced
this pull request
Oct 3, 2026
Keeps the commit-hash-pinned third-party actions in .github/workflows up to date: Dependabot bumps the SHA and the trailing version comment together, grouped into one weekly PR. Ported from OpenIdentityPlatform/OpenIG#170.
vharseko
added a commit
to vharseko/OpenIDM
that referenced
this pull request
Oct 5, 2026
Keeps the commit-hash-pinned third-party actions in .github/workflows up to date: Dependabot bumps the SHA and the trailing version comment together, grouped into one weekly PR. Ported from OpenIdentityPlatform/OpenIG#170.
vharseko
added a commit
to OpenIdentityPlatform/OpenIDM
that referenced
this pull request
Oct 6, 2026
* Harden GitHub workflows and SMTP STARTTLS trust - Set an explicit read-only GITHUB_TOKEN permissions block on the build, deploy and release workflows, elevating only the jobs that need it (wiki/docs push and release tag: contents:write; ghcr push: packages:write) - Pin the third-party docker/* and softprops/action-gh-release actions to commit SHAs - EmailClient: stop trusting every SMTP server certificate over STARTTLS; validation is now the default, with opt-in starttls.trustedHosts / starttls.trustAll settings (documented) Resolves CodeQL alerts #711-#716, #718-#738, #920, #921 (actions) and #22 (java/insecure-smtp-ssl). * Add .github/dependabot.yml for the SHA-pinned actions Keeps the commit-hash-pinned third-party actions in .github/workflows up to date: Dependabot bumps the SHA and the trailing version comment together, grouped into one weekly PR. Ported from OpenIdentityPlatform/OpenIG#170. * Address review on STARTTLS trust: host check, trustedHosts, Admin UI - Validate the SMTP certificate's host name by default (mail.smtp.ssl.checkserveridentity=true); JavaMail 1.4.7 leaves it off - Exclude jakarta.mail from the email bundle's classpath: compiling against its com.sun.mail.util made the bundle import MailSSLSocketFactory from jakarta.mail, which javax.mail's SocketFetcher does not recognise, so starttls.trustedHosts trusted every host - Warn when starttls.trustedHosts does not contain the SMTP host - Admin UI: keep starttls.trustedHosts/trustAll when saving the Email form - Tests: host check, trustAll precedence, socket factory origin - Docs: host match, exact trustedHosts entry, trustAll precedence * Embed javax.mail in the email bundle and enable current TLS for STARTTLS The com.sun.mail.util [1.4,2) import from the previous commit left openidm-external-email unresolved, so OpenIDM never reached "ready" in CI: javax.mail 1.4.7 imports its own com.sun.mail.* packages with no upper bound, Felix wires them to jakarta.mail 2.0.2 and drops the 1.4.7 exports. The same wiring already broke mail on master, where MimeMessage fails with NoSuchMethodError on com.sun.mail.util.PropUtil. - Embed javax.mail 1.4.7 in the bundle so Session, SMTPTransport, SocketFetcher and MailSSLSocketFactory come from one jar, and point the context class loader at the bundle while JavaMail loads its providers. - Set mail.smtp.ssl.protocols to the JVM defaults when STARTTLS is on. Without it JavaMail 1.4.7 enables only TLSv1, which current JDKs disable, so no STARTTLS handshake could succeed. * Address review round 2 on STARTTLS trust: IP SAN note and tests - chap-mail.adoc: on Java 17+ the host is matched only against DNS SANs (or the CN), so a relay addressed by IP is rejected even with an IP SAN - EmailClientTest: replace withoutStartTlsNoSocketFactoryIsConfigured with trustSettingsApplyOnlyWithStartTls, which fails if the trust settings are applied outside STARTTLS - EmailConfigViewTest: pin that saving Settings > Email keeps starttls.trustedHosts and starttls.trustAll
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the 16 open
mediumcode scanning alerts in.github/workflows(actions/missing-workflow-permissions#70–#73, #85 andactions/unpinned-tag#74–#84).Explicit
GITHUB_TOKENpermissionspermissionsbuild.yml(workflow-level)localhost:5000contents: readrelease.yml/release-mavenmvn release:preparepushes commits + tag,action-gh-release, wiki pushcontents: writerelease.yml/release-dockerdocker/login-actionto GHCR withGITHUB_TOKENcontents: read,packages: writedeploy.yml/deploy-mavencontents: writeThird-party actions pinned to commit SHAs
docker/metadata-actionv6.2.0,docker/setup-qemu-actionv4.4.0,docker/setup-buildx-actionv4.4.1,docker/login-actionv4.6.0,docker/build-push-actionv7.4.0,softprops/action-gh-releasev3.0.3 — each as@<sha> # vX.Y.Z.actions/*andgithub/codeql-actionstay on major tags (first-party, not flagged by CodeQL).Actions updated to the latest releases
actions/checkoutv6 → v7actions/setup-javav5 → v6actions/cachev5 → v6softprops/action-gh-releasev2 → v3.0.3 (Node 24 runtime)Release notes checked for breaking changes: checkout v7 only blocks fork-PR checkouts under
pull_request_target/workflow_run(ourdeploy.ymljob only runs forpushevents of the base repo); setup-java v6 and cache v6 are ESM migrations with no input changes..github/dependabot.ymlNew:
github-actionsecosystem, weekly, all action updates grouped into a single PR with labelsci+dependencies. Dependabot updates the pinned SHA and the# vX.Y.Zcomment together, so the pins do not go stale.Note for the reviewer
The
permissionsblocks forrelease.ymlanddeploy.ymlcan only be fully validated by a real release / deploy run. The wiki and doc-site steps arecontinue-on-error: true, so a missing permission there would not fail the workflow but would silently skip the publish — worth a glance at the logs of the first run after merge.