Skip to content

fix: bind the reusable CI job token during setup - #31

Merged
mindburnlabs merged 1 commit into
mainfrom
g0-ci-setup-token-d36
Oct 4, 2026
Merged

mindburnlabs merged 1 commit into
mainfrom
g0-ci-setup-token-d36

Conversation

@mindburnlabs

Copy link
Copy Markdown
Contributor

Fix the actual reusable workflow token context

GitOps #341 readback run 37218295591 confirms that a caller's with.setup-commands interpolates github.token as empty. The private base fetch then fails with exit 128 before the G0 guard. The same issue would prevent canonical PR/Actions reads later.

Bind the callee's actual short-lived job token as GH_TOKEN in its setup step after the job starts. Caller and callee retain the existing contents/actions/pull-requests read permissions. Checkout still persists no credentials; GitOps uses a command-local helper. No static credential, new scope, App widening or global Git config.

make check passed actionlint/shellcheck and all 36 controls. GitOps will pin the exact merged commit and consume the runtime variable; its hosted CI is the required behavior readback. No moving v2 tag or broad rollout.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T17:00:44.694582Z 277950d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mindburnlabs
mindburnlabs enabled auto-merge (squash) October 4, 2026 16:58
@mindburnlabs
mindburnlabs merged commit 8e3aa09 into main Oct 4, 2026
7 checks passed
@mindburnlabs
mindburnlabs deleted the g0-ci-setup-token-d36 branch October 4, 2026 16:59

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 277950da57

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
COMMANDS: ${{ inputs.setup-commands }}
# The caller's `with` context has no job token yet. Bind the
# short-lived read token here, after this reusable job has started.
GH_TOKEN: ${{ github.token }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep the job token out of dependency setup

When setup-commands executes repository-controlled code—most notably the documented npm ci example—package lifecycle scripts from a pull request inherit GH_TOKEN. An untrusted or compromised dependency can therefore exfiltrate this token and use its contents, actions, and pull-requests read access, including against private repositories and workflow artifacts. Provide the token only to a narrowly scoped authenticated Git operation rather than every process spawned by the generic setup command.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant