Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@ jobs:
outputs:
ansible: ${{ steps.filter.outputs.ansible }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2
Comment on lines +30 to +31

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Inspect the workflow file around the cited lines.
git ls-files .github/workflows/ci.yml
wc -l .github/workflows/ci.yml
sed -n '1,220p' .github/workflows/ci.yml | cat -n

# Look for any subsequent git push/auth usage that would require persisted credentials.
rg -n --no-heading -S 'git (push|fetch|submodule|clone)|github\.token|persist-credentials|checkout@' .github/workflows/ci.yml

Repository: decdn/devops

Length of output: 8141


Disable persisted credentials on each checkout step. .github/workflows/ci.yml:30,48,80,120,155 These jobs only lint/build/scan and never need repo auth, so add persist-credentials: false to every actions/checkout invocation to keep the token out of .git/config.

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 30-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 30 - 31, The workflow’s checkout steps
are leaving repo credentials persisted even though these jobs only
lint/build/scan and do not need git auth. Update every actions/checkout
invocation in the CI workflow to set persist-credentials to false so the token
is not written into .git/config; make this change consistently wherever checkout
is used.

Source: Linters/SAST tools

id: filter
with:
filters: |
Expand All @@ -45,8 +45,8 @@ jobs:
run:
working-directory: ansible
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.12'
- name: Install Ansible tooling
Expand Down Expand Up @@ -77,8 +77,8 @@ jobs:
run:
working-directory: ansible
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.12'
- name: Install build + import tooling
Expand Down Expand Up @@ -117,7 +117,7 @@ jobs:
if: needs.changes.outputs.ansible == 'true'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: KICS Ansible security scan (fail on HIGH)
# master @ 2026-05-22 "[StepSecurity] Apply security best practices (#157)"
uses: Checkmarx/kics-github-action@7117906d8779ecaf5180f34c4931a774f10d7625
Expand Down Expand Up @@ -152,7 +152,7 @@ jobs:
contents: read
checks: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: reviewdog/action-actionlint@6fb7acc99f4a1008869fa8a0f09cfca740837d9d # v1.72.0
with:
reporter: github-check
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/molecule.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,8 @@ jobs:
run:
working-directory: ansible
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
Comment on lines +28 to +29

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Show the workflow around the referenced lines with numbers.
sed -n '1,120p' .github/workflows/molecule.yml | cat -n

Repository: decdn/devops

Length of output: 1562


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Check whether the Molecule job or Ansible test setup depends on git credentials or submodules.
rg -n --hidden --glob '!**/.git/**' \
  -e 'submodule' -e 'git ' -e 'github.token' -e 'GITHUB_TOKEN' -e 'persist-credentials' \
  .github ansible

Repository: decdn/devops

Length of output: 257


Disable persisted credentials on checkout. This job only runs Molecule tests, so the GitHub token does not need to remain in git config. Set persist-credentials: false on actions/checkout to reduce token exposure.

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 28-28: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/molecule.yml around lines 28 - 29, Update the Molecule
workflow’s actions/checkout step to disable persisted GitHub credentials by
setting persist-credentials to false. This job only runs tests, so adjust the
checkout configuration directly in the checkout action entry to prevent the
token from being stored in git config and reduce exposure.

Source: Linters/SAST tools

with:
python-version: '3.12'
- name: Install molecule + Ansible
Expand Down
Loading