Repository navigation
security updates - #1495
security updates#1495alexcos20 wants to merge 2 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe changes update Dependabot schedules and GitHub workflow actions and permissions. CI passes Docker registry credentials through step outputs. The n8n security-scan workflow adds comment and author checks, builds its payload with ChangesWorkflow maintenance
Security-scan webhook
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant GitHubComment
participant GitHubActions
participant N8NWebhook
GitHubComment->>GitHubActions: Created pull-request comment event
GitHubActions->>GitHubActions: Check pull request, command, and author association
GitHubActions->>N8NWebhook: POST jq-built payload with bearer token
Merge Risk: ⚪ Minimal · up to No actionable merge-blocking issue is established. The credential changes preserve their identified consumers, and GHCR operations do not depend on the restricted workflow token. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
CI/CD security hardening (
security/202610_updates)Review-driven hardening of GitHub Actions CI and Dependabot. Only
.github/is touched.Changes
Dependabot —
.github/dependabot.yml(new)cooldown: { default-days: 7 }— only versions public for ≥7 days are proposed.Workflows
ci.ymltest_integrationandtest_systemjobs built aDOCKER_REGISTRY_AUTHSJSON (containing the Docker Hub password) and wrote it to$GITHUB_ENV, which persists it into the environment of every later step — including the test runs that execute dependency/third-party code. It is now written to a scoped step output (steps.docker_auths.outputs.value) and consumed only by the one step that needs it.permissions: contents: read.actions/checkout@v7,actions/setup-node@v7,actions/cache@v6,actions/upload-artifact@v7,actions/download-artifact@v8.docker.yml— added top-levelpermissions: contents: read; updatedactions/*anddocker/*to latest.ghcr_cleanup.yml— added top-levelpermissions: contents: read; pinned the third-party actiondataaxiom/ghcr-cleanup-action(which holds a package-delete-capable PAT) to a full commit SHA (d52806a0…, v1.2.2); updateddocker/login-action@v4.Workflow —
n8n.yml(security hardening)jqfromenv:vars — closes the shell/JSON injection in the old${{ … }}-into-heredoc pattern./run-security-scanon a PR) but is now gated to trusted commenters (author_association∈ OWNER/MEMBER/COLLABORATOR).permissions: {}(noGITHUB_TOKENscope).Authorization: Bearerheader.N8N_BEARER_TOKEN; without it the step sends an empty bearer.Checkout credential hardening —
persist-credentials: falseactions/checkoutwrites the job'sGITHUB_TOKENinto.git/config(as anhttp.extraheader) by default, where any later step can read it — includingnpm ci/npm install, whose dependency install scripts run arbitrary code. ScopingNODE_AUTH_TOKENto the publish steps does not cover this separate Git credential.persist-credentials: falseto all 13actions/checkoutstep(s) in this repo. None of these jobs perform authenticated Git operations after checkout, so nothing else is needed.persist-credentialsonly affect what's written to disk; the checkout itself still authenticates normally.Review / testing notes
download-artifact→v8 changed behavior (fails on digest mismatch, no auto-decompress) — the docker digest-merge flow relies on it; validate a docker build+merge run.ci.ymlhas anif:referencingenv.DOCKERHUB_PASSWORDNONO/…USERNAMENONO(typo'd vars) so that one Docker Hub login step never runs. Worth a separate fix.Summary by CodeRabbit