Skip to content

ci: harden workflows against zizmor cache-poisoning (high) and artipacked (medium) findings #156

Description

@thewrz

This was written agentically; verify its assertions:

What

Running zizmor (v1.30.1, offline mode) over .github/workflows/ during the dependency triage on 2026-09-15 reports one high and eight medium findings. All are pre-existing on main (byte-identical before and after the action bumps in #154), so they were deliberately left out of that PR.

high — cache-poisoning (build-server.yml:45, confidence: low)
actions/setup-node v5+ enables package-manager-cache by default. build-server.yml runs on push/release/workflow_dispatch and publishes release artifacts, so a poisoned npm cache could reach a published build. Fix candidates: set package-manager-cache: false on the setup-node step in build-server.yml only (CI can keep the cache), or split artifact publishing into a job with caching off.

medium — artipacked ×8 (every actions/checkout step)
persist-credentials defaults to true, so the GITHUB_TOKEN is written into .git/config and could leak through any uploaded artifact. Fix: with: persist-credentials: false on each checkout that does not need to push.

Reference: https://docs.zizmor.sh/audits/#cache-poisoning and https://docs.zizmor.sh/audits/#artipacked

Why an issue and not a PR

Workflow hardening changes CI behaviour and should be reviewed on their own, not smuggled into a dependency bump.

🤖 Co-authored by Claude Fable 5.1.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ciCI and workflow changesenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions