Repository navigation
fix: bind the reusable CI job token during setup - #31
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 277950da57
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| COMMANDS: ${{ inputs.setup-commands }} | ||
| # The caller's `with` context has no job token yet. Bind the | ||
| # short-lived read token here, after this reusable job has started. | ||
| GH_TOKEN: ${{ github.token }} |
There was a problem hiding this comment.
Keep the job token out of dependency setup
When setup-commands executes repository-controlled code—most notably the documented npm ci example—package lifecycle scripts from a pull request inherit GH_TOKEN. An untrusted or compromised dependency can therefore exfiltrate this token and use its contents, actions, and pull-requests read access, including against private repositories and workflow artifacts. Provide the token only to a narrowly scoped authenticated Git operation rather than every process spawned by the generic setup command.
Useful? React with 👍 / 👎.
Fix the actual reusable workflow token context
GitOps #341 readback run 37218295591 confirms that a caller's
with.setup-commandsinterpolatesgithub.tokenas empty. The private base fetch then fails with exit 128 before the G0 guard. The same issue would prevent canonical PR/Actions reads later.Bind the callee's actual short-lived job token as
GH_TOKENin its setup step after the job starts. Caller and callee retain the existing contents/actions/pull-requests read permissions. Checkout still persists no credentials; GitOps uses a command-local helper. No static credential, new scope, App widening or global Git config.make checkpassed actionlint/shellcheck and all 36 controls. GitOps will pin the exact merged commit and consume the runtime variable; its hosted CI is the required behavior readback. No movingv2tag or broad rollout.