mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-04 02:31:36 +00:00
Collapse release-candidate.yml into publish.yml so there is exactly one workflow that publishes gitnexus to npm, creates GitHub Releases, and triggers Docker builds — for both release candidates and stable releases. Closes #1609 architecturally.
A first-stage `route` job classifies push-to-main / push-tag / workflow_dispatch into `rc` / `stable` modes and fails closed on malformed shapes. RC path runs rc-guard → ci.yml → publish (mint GitHub App token → checkout with persist-credentials:false → resolve next rc version → atomic v-tag + rc/<SHA> marker push → vtag integrity gate → npm publish via OIDC → GitHub prerelease → if: failure() cleanup) → docker.yml. Stable path verifies package.json matches the tag and publishes to `latest` via OIDC (no docker).
Hardening:
• Self-trigger prevention via negative-glob `tags: ['v*', '!v*-rc.*']` — the bug class behind #1609 cannot recur.
• Two distinct actions/checkout steps per mode (no conditional `token:` expression footgun).
• Workflow-level `permissions: {}` deny-all + per-job grants; `id-token: write` only where OIDC is used.
• npm Trusted Publishing replaces NPM_TOKEN (delete the secret after the first successful publish).
• GitHub App installation token (actions/create-github-app-token@v3.2.0) replaces the long-lived RELEASE_PUSH_TOKEN PAT (delete after first successful RC).
• vtag integrity gate fails closed on empty / mode-mismatched output (prevents Release named `main` from a github.ref fallback).
• Annotation-injection sanitization on every logged ref.
• Explicit `secrets:` passthrough on docker.yml (DOCKERHUB_USERNAME, DOCKERHUB_TOKEN); ci.yml no longer inherits anything.
• `if: failure()` cleanup auto-deletes v-tag + rc-marker on partial failure (eliminates the external-consumer phantom-version ingestion window).
• ACTIONS_STEP_DEBUG window closed via `set +x` wrap on the inline auth-header compute.
• Curated retry-loud error handling on `gh api` bot-user-id lookup and `npx semver`.
Pre-merge validation:
• 10-reviewer multi-agent code-review pass; 14 findings fixed inline (commit 820cefae), 6 deferred to follow-ups.
• End-to-end dry-run rehearsal via workflow_dispatch (run 25919563064) validated route classification, rc-guard, App token mint, RC checkout, version resolver, vtag synthetic-regex check, and faithful tarball pack at the bumped version.
• All zizmor findings on the unification commits closed.
• Branch-protection required checks all green.
Post-merge actions:
• After the first successful RC, delete the `NPM_TOKEN` and `RELEASE_PUSH_TOKEN` secrets — they are no longer used.
• The first real RC after merge is the live-fire test for steps dry-run could not exercise (atomic tag push, real npm OIDC handshake, GitHub Release creation, docker.yml under explicit secrets passthrough). The if: failure() cleanup step handles the partial-failure recovery automatically; the Rollback Runbook in CONTRIBUTING.md covers the rare cases auto-cleanup can't reach.
44 lines
2.3 KiB
YAML
44 lines
2.3 KiB
YAML
# zizmor config — pre-existing intentional patterns flagged on initial introduction.
|
|
# Each ignore below has a documented mitigation. Re-evaluate when the source workflow changes.
|
|
#
|
|
# To run zizmor locally with this config:
|
|
# zizmor --config .github/zizmor.yml .
|
|
|
|
rules:
|
|
dangerous-triggers:
|
|
ignore:
|
|
# workflow_run is REQUIRED to post sticky comments on fork PRs — the
|
|
# default-branch privileged token isn't accessible from `pull_request`
|
|
# on a fork. Mitigated by: read-only `actions:read` + `contents:read`
|
|
# for artifact download; `pull-requests:write` is the only write scope;
|
|
# no checkout of fork code occurs. Header comment in the file documents.
|
|
- ci-report.yml
|
|
|
|
# workflow_run is the trusted half of the autofix pipeline. The
|
|
# untrusted half (pr-autofix.yml) runs fork code with permissions:{}
|
|
# and produces only a diff artifact (data, not executable code). The
|
|
# publish job consumes the artifact, allowlist-validates every field
|
|
# of metadata.json before exporting to $GITHUB_OUTPUT, never checks
|
|
# out fork code, and never executes anything fork-controlled. Header
|
|
# comment in the file documents the split.
|
|
- pr-autofix-publish.yml
|
|
|
|
# pull_request_target needed by claude-code-action to access secrets
|
|
# and post review comments on fork PRs. Mitigated by: PR checkouts pin
|
|
# the fork's HEAD SHA (not the branch ref) to prevent TOCTOU races,
|
|
# and claude-code-action sandboxes execution. Header comment documents.
|
|
- claude.yml
|
|
|
|
# pull_request_target on the autolabel job needs `pull-requests:write`
|
|
# to apply labels. Mitigated by: release-drafter runs with `dry-run:
|
|
# true`, reads only `.github/release-drafter.yml` from the BASE ref,
|
|
# and the validate-title job (which runs untrusted `pull_request`
|
|
# context) holds no write permissions. Header comment documents.
|
|
- pr-labeler.yml
|
|
|
|
# Note: cache-poisoning is NOT exempted. The two prior findings in
|
|
# publish.yml and the former release-candidate.yml were fixed structurally
|
|
# by dropping `cache: npm` from those workflows (matches the pattern used
|
|
# by PyO3/maturin for the same audit). After the publish-workflow
|
|
# unification (issue #1609), only publish.yml remains; the same
|
|
# cache-poisoning hardening applies there.
|