-
-
Notifications
You must be signed in to change notification settings - Fork 0
Refuse unimplemented certificate verification #33
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,4 @@ | ||
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| # This workflow is managed by gh actions-lock. | ||
|
|
@@ -36,7 +37,7 @@ jobs: | |
| build-mode: none | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@v4.37.9 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🤖 get_repo_knowledge executed:
Length of output: 1187 🏁 Script executed: #!/bin/sh
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/codeql.yml
printf '%s\n' '--- action references ---'
rg -n 'github/codeql-action/(init|analyze)@' .github/workflowsRepository: hyperpolymath/lithoglyph Length of output: 2399 🏁 Script executed: #!/bin/sh
set -eu
repo=github/codeql-action
tag=v4.37.9
ref=$(gh api "repos/$repo/git/refs/tags/$tag")
printf '%s\n' "$ref"
type=$(printf '%s' "$ref" | jq -r '.object.type')
sha=$(printf '%s' "$ref" | jq -r '.object.sha')
if [ "$type" = tag ]; then
sha=$(gh api "repos/$repo/git/tags/$sha" --jq '.object.sha')
fi
printf 'dereferenced commit: %s\n' "$sha"
gh api "repos/$repo/commits/$sha" --jq '.sha'Repository: hyperpolymath/lithoglyph Length of output: 611 Pin both CodeQL actions to a commit SHA. Replace both 🧰 Tools🪛 zizmor (1.29.0)[error] 42-42: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI Agents |
||
| with: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,4 @@ | ||
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| # This workflow is managed by gh actions-lock. | ||
|
|
@@ -32,7 +33,7 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🤖 get_repo_knowledge executed:
Length of output: 1182 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- checkout references ---'
rg -n -C 5 'uses: actions/checkout@|persist-credentials:|pull_request|pull_request_target|workflow_dispatch' \
.github/workflows/dogfood-gate.yml \
.github/workflows/e2e.yml \
.github/workflows/estate-rules.yml \
.github/workflows/static-analysis-gate.yml \
.github/workflows/test-suite.yml \
.github/workflows/zig-tests.yml
printf '%s\n' '--- post-checkout executable steps ---'
for f in \
.github/workflows/dogfood-gate.yml \
.github/workflows/e2e.yml \
.github/workflows/estate-rules.yml \
.github/workflows/static-analysis-gate.yml \
.github/workflows/test-suite.yml \
.github/workflows/zig-tests.yml
do
printf '\n### %s\n' "$f"
cat -n "$f"
doneRepository: hyperpolymath/lithoglyph Length of output: 50381 🏁 Script executed: #!/bin/bash
set -eu
for f in \
.github/workflows/dogfood-gate.yml \
.github/workflows/e2e.yml \
.github/workflows/estate-rules.yml \
.github/workflows/static-analysis-gate.yml \
.github/workflows/test-suite.yml \
.github/workflows/zig-tests.yml
do
printf '\n### %s\n' "$f"
rg -n -C 6 'uses: actions/checkout@|persist-credentials:|pull_request|pull_request_target|run:|uses:' "$f"
doneRepository: hyperpolymath/lithoglyph Length of output: 42219 🤖 get_repo_knowledge executed:
Length of output: 1169 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- checkout references and workflow triggers ---'
rg -n -C 4 'uses: actions/checkout@|persist-credentials:|^[[:space:]]*(pull_request|pull_request_target|workflow_dispatch):' .github/workflows
printf '%s\n' '--- relevant job commands ---'
rg -n -C 8 'uses: actions/checkout@|run:|uses:' \
.github/workflows/dogfood-gate.yml \
.github/workflows/e2e.yml \
.github/workflows/estate-rules.yml \
.github/workflows/static-analysis-gate.yml \
.github/workflows/test-suite.yml \
.github/workflows/zig-tests.ymlRepository: hyperpolymath/lithoglyph Length of output: 50381 🌐 Web query:
💡 Result: In actions/checkout version 7.0.1, the persist-credentials input defaults to true [1][2]. When persist-credentials is set to its default value (true), the action configures the authentication token or SSH key used for the checkout within the local git configuration [3][4][5]. This allows subsequent git commands executed within your workflow scripts to run in an authenticated context [3][6][7]. The action ensures the token is removed during the post-job cleanup process [3][4]. If you wish to prevent the action from configuring your credentials in the local git config, you can explicitly set persist-credentials to false [3][5]. Citations:
🏁 Script executed: #!/bin/bash
set -eu
for f in .github/workflows/dogfood-gate.yml .github/workflows/e2e.yml .github/workflows/estate-rules.yml .github/workflows/static-analysis-gate.yml .github/workflows/test-suite.yml .github/workflows/zig-tests.yml; do
echo "### $f"
grep -n -E '^(on:|[[:space:]]+(pull_request|pull_request_target|push|workflow_dispatch):)|uses: actions/checkout@|persist-credentials:|run:' "$f"
doneRepository: hyperpolymath/lithoglyph Length of output: 5347 Disable checkout credential persistence on every active checkout in these workflows. These workflows run on 🧰 Tools🪛 zizmor (1.29.0)[warning] 35-36: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) 📍 Affects 6 files
🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
|
|
||
| - name: Check for A2ML files | ||
| id: detect | ||
|
|
@@ -83,7 +84,7 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Check for K9 files | ||
| id: detect | ||
|
|
@@ -135,7 +136,7 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Scan for invisible characters | ||
| id: lint | ||
|
|
@@ -200,7 +201,7 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Check for Groove manifest | ||
| id: groove | ||
|
|
@@ -265,7 +266,7 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Check and validate eclexiaiser manifest | ||
| id: eclex | ||
|
|
@@ -317,7 +318,7 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Generate dogfooding scorecard | ||
| run: | | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,4 @@ | ||
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| name: Label Triage | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,4 @@ | ||
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| name: Labels | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🤖 get_repo_knowledge executed:
get_repo_knowledge hyperpolymath/lithoglyph /tmp/coderabbit-repo-knowledge/hyperpolymath-lithoglyph-fdc9ff92Length of output: 1181
🏁 Script executed:
Repository: hyperpolymath/lithoglyph
Length of output: 39538
🌐 Web query:
official actions/checkout v7 persist-credentials default GitHub README💡 Result:
In
actions/checkout@v7, the default value for thepersist-credentialsinput istrue[1][2][3]. This input determines whether the authentication token (or SSH key) used to check out the repository is persisted in the local Git configuration [4][5][6]. When set totrue(the default), the action configures the Git environment to enable your workflow scripts to run authenticated Git commands (such asgit push) [4][7]. The token is subsequently removed during the post-job cleanup phase [4][8][6]. If you prefer not to persist these credentials, you can opt out by explicitly setting the input tofalsein your workflow configuration [4][5][9]: - uses: actions/checkout@v7 with: persist-credentials: falseCitations:
Disable GitHub token persistence for the six listed workflow checkouts.
actions/checkout@v7persistsGITHUB_TOKENin local Git configuration by default. Later repository commands or third-party actions can read this token. Addpersist-credentials: falseto each checkout unless a later step requires authenticated Git operations.🧰 Tools
🪛 zizmor (1.29.0)
[warning] 34-35: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
📍 Affects 4 files
.github/workflows/ci.yml#L35-L35(this comment).github/workflows/ci.yml#L69-L69.github/workflows/ci.yml#L97-L97.github/workflows/codeql.yml#L40-L40.github/workflows/container-build.yml#L36-L36.github/workflows/sonarqube.yml#L30-L30🤖 Prompt for AI Agents
Source: Linters/SAST tools