Skip to content

security updates - #1495

Open
alexcos20 wants to merge 2 commits into
mainfrom
security/202610_updates
Open

alexcos20 wants to merge 2 commits into
mainfrom
security/202610_updates

Conversation

@alexcos20

@alexcos20 alexcos20 commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

CI/CD security hardening (security/202610_updates)

Review-driven hardening of GitHub Actions CI and Dependabot. Only .github/ is touched.

Changes

Dependabot — .github/dependabot.yml (new)

  • Added Dependabot covering npm, github-actions, and docker, weekly.
  • Each ecosystem uses cooldown: { default-days: 7 } — only versions public for ≥7 days are proposed.

Workflows

  • ci.yml
    • Credential-leak fix: the test_integration and test_system jobs built a DOCKER_REGISTRY_AUTHS JSON (containing the Docker Hub password) and wrote it to $GITHUB_ENV, which persists it into the environment of every later step — including the test runs that execute dependency/third-party code. It is now written to a scoped step output (steps.docker_auths.outputs.value) and consumed only by the one step that needs it.
    • Added top-level permissions: contents: read.
    • Updated actions: actions/checkout@v7, actions/setup-node@v7, actions/cache@v6, actions/upload-artifact@v7, actions/download-artifact@v8.
  • docker.yml — added top-level permissions: contents: read; updated actions/* and docker/* to latest.
  • ghcr_cleanup.yml — added top-level permissions: contents: read; pinned the third-party action dataaxiom/ghcr-cleanup-action (which holds a package-delete-capable PAT) to a full commit SHA (d52806a0…, v1.2.2); updated docker/login-action@v4.

Workflow — n8n.yml (security hardening)

  • Reworked the "Trigger N8N Security Scan" workflow (previously flagged as unsafe):
    • Payload is now built with jq from env: vars — closes the shell/JSON injection in the old ${{ … }}-into-heredoc pattern.
    • Trigger stays comment-based (/run-security-scan on a PR) but is now gated to trusted commenters (author_association ∈ OWNER/MEMBER/COLLABORATOR).
    • Job runs with permissions: {} (no GITHUB_TOKEN scope).
    • The webhook call now sends an Authorization: Bearer header.
  • Action required: create a repo secret N8N_BEARER_TOKEN; without it the step sends an empty bearer.

Checkout credential hardening — persist-credentials: false

  • actions/checkout writes the job's GITHUB_TOKEN into .git/config (as an http.extraheader) by default, where any later step can read it — including npm ci/npm install, whose dependency install scripts run arbitrary code. Scoping NODE_AUTH_TOKEN to the publish steps does not cover this separate Git credential.
  • Added persist-credentials: false to all 13 actions/checkout step(s) in this repo. None of these jobs perform authenticated Git operations after checkout, so nothing else is needed.
  • Note: cooldowns/persist-credentials only affect what's written to disk; the checkout itself still authenticates normally.

Review / testing notes

  • download-artifact→v8 changed behavior (fails on digest mismatch, no auto-decompress) — the docker digest-merge flow relies on it; validate a docker build+merge run.
  • Registry credentials remain step-scoped and gated on secret presence; fork PRs still skip login/push.
  • Unrelated pre-existing bug spotted (not fixed here): ci.yml has an if: referencing env.DOCKERHUB_PASSWORDNONO/…USERNAMENONO (typo'd vars) so that one Docker Hub login step never runs. Worth a separate fix.
  • All new action majors run on Node 24; runners are GitHub-hosted, so no runner change is needed.

Summary by CodeRabbit

  • Chores
    • Automated weekly update proposals are now configured for project dependencies and build tools.
    • Build, test, and image publishing workflows use updated automation tools.
  • Security
    • Workflows now use restricted repository permissions.
    • Security scans can be triggered from pull request comments only by authorized contributors using the designated command.
    • Webhook requests now use bearer-token authentication, with safer handling of input values.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 563a69e4-f9ab-4ada-9280-505a71346cce

📥 Commits

Reviewing files that changed from the base of the PR and between 0b24e34 and d1f56bf.


📒 Files selected for processing (5)
  • .github/dependabot.yml
  • .github/workflows/ci.yml
  • .github/workflows/docker.yml
  • .github/workflows/ghcr_cleanup.yml
  • .github/workflows/n8n.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



📝 Walkthrough

Walkthrough

The changes update Dependabot schedules and GitHub workflow actions and permissions. CI passes Docker registry credentials through step outputs. The n8n security-scan workflow adds comment and author checks, builds its payload with jq, and authenticates its webhook request.

Changes

Workflow maintenance

Layer / File(s) Summary
Dependabot update schedules
.github/dependabot.yml
Adds weekly npm, GitHub Actions, and Docker update schedules from /, with a seven-day default cooldown for each ecosystem.
CI workflow updates
.github/workflows/ci.yml
Sets read-only contents permission and updates action versions across CI jobs. Integration and system jobs expose Docker registry credentials as step outputs and pass those outputs to their consumers.
Image publishing and cleanup workflows
.github/workflows/docker.yml, .github/workflows/ghcr_cleanup.yml
Updates actions used for x86 and ARM image builds, image merging, and GHCR cleanup. The workflows explicitly set contents permissions.

Security-scan webhook

Layer / File(s) Summary
Scan trigger and authenticated request
.github/workflows/n8n.yml
Restricts scan runs to qualifying pull-request comments from specified author associations. Builds the payload with jq and sends it with a bearer token.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant GitHubComment
  participant GitHubActions
  participant N8NWebhook
  GitHubComment->>GitHubActions: Created pull-request comment event
  GitHubActions->>GitHubActions: Check pull request, command, and author association
  GitHubActions->>N8NWebhook: POST jq-built payload with bearer token
Loading

Merge Risk: ⚪ Minimal · up to d1f56

No actionable merge-blocking issue is established. The credential changes preserve their identified consumers, and GHCR operations do not depend on the restricted workflow token.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title is related to the pull request because the changes update action versions, restrict workflow permissions, protect credentials, and harden webhook handling. It is broad but still communicates…


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant