diff --git a/.github/workflows/benchmark-release.yml b/.github/workflows/benchmark-release.yml index 59e8497..9fe7bea 100644 --- a/.github/workflows/benchmark-release.yml +++ b/.github/workflows/benchmark-release.yml @@ -26,13 +26,14 @@ on: schedule: - cron: "0 * * * *" -permissions: - actions: write - contents: write +permissions: {} jobs: discover: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write outputs: has_runs: ${{ steps.discover.outputs.has_runs }} matrix: ${{ steps.discover.outputs.matrix }} @@ -40,6 +41,8 @@ jobs: AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }} SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }} steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Ensure AWS credentials are configured run: | if [ -z "${{ secrets.AWS_ACCESS_KEY_ID }}" ] || [ -z "${{ secrets.AWS_SECRET_ACCESS_KEY }}" ]; then @@ -174,6 +177,9 @@ jobs: needs: discover if: ${{ needs.discover.outputs.has_runs == 'true' }} runs-on: ubuntu-latest + permissions: + contents: write + id-token: write strategy: fail-fast: false matrix: ${{ fromJson(needs.discover.outputs.matrix) }} @@ -181,6 +187,8 @@ jobs: AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }} SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }} steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: @@ -547,7 +555,13 @@ jobs: needs: [discover, release] if: ${{ needs.discover.outputs.has_runs == 'true' && needs.release.result == 'success' }} runs-on: ubuntu-latest + permissions: + actions: write + contents: read + id-token: write steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Trigger docs refresh env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/benchmark-request.yml b/.github/workflows/benchmark-request.yml index 8fa154f..d41e9ba 100644 --- a/.github/workflows/benchmark-request.yml +++ b/.github/workflows/benchmark-request.yml @@ -4,9 +4,7 @@ on: issues: types: [opened, edited, labeled] -permissions: - contents: read - issues: write +permissions: {} concurrency: group: benchmark-request-${{ github.event.issue.number }} @@ -15,6 +13,10 @@ concurrency: jobs: prepare: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write + issues: write outputs: is_request: ${{ steps.prepare.outputs.is_request }} should_run: ${{ steps.prepare.outputs.should_run }} @@ -35,6 +37,8 @@ jobs: properties_path: ${{ steps.prepare.outputs.properties_path }} fuzzer_env_json: ${{ steps.prepare.outputs.fuzzer_env_json }} steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Parse and validate benchmark request id: prepare uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7 @@ -454,6 +458,9 @@ jobs: benchmark-run: needs: prepare if: ${{ needs.prepare.outputs.should_run == 'true' }} + permissions: + contents: read + id-token: write uses: ./.github/workflows/benchmark-run.yml secrets: inherit with: @@ -480,7 +487,10 @@ jobs: runs-on: ubuntu-latest permissions: issues: write + id-token: write steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Comment result (and close on success) uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7 with: diff --git a/.github/workflows/benchmark-run.yml b/.github/workflows/benchmark-run.yml index 131f7c3..9c51017 100644 --- a/.github/workflows/benchmark-run.yml +++ b/.github/workflows/benchmark-run.yml @@ -180,12 +180,14 @@ on: description: "Benchmark UUID (derived from manifest)." value: ${{ jobs.benchmark-run.outputs.benchmark_uuid }} -permissions: - contents: read +permissions: {} jobs: benchmark-run: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write outputs: run_id: ${{ steps.tf_outputs.outputs.run_id }} benchmark_uuid: ${{ steps.tf_outputs.outputs.benchmark_uuid }} @@ -193,6 +195,8 @@ jobs: AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }} SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }} steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e65e64f..836ff01 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,13 +7,17 @@ on: - main workflow_dispatch: -permissions: - contents: read +permissions: {} jobs: actionlint: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: @@ -43,7 +47,12 @@ jobs: terraform: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: @@ -75,7 +84,12 @@ jobs: python: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: @@ -101,7 +115,12 @@ jobs: docs: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: diff --git a/.github/workflows/dependency-scan.yml b/.github/workflows/dependency-scan.yml new file mode 100644 index 0000000..30c2e17 --- /dev/null +++ b/.github/workflows/dependency-scan.yml @@ -0,0 +1,13 @@ +name: Dependency Scan + +"on": + pull_request: + +permissions: {} + +jobs: + dependency-scan: + uses: tempoxyz/gh-actions/.github/workflows/dependency-scan.yml@25cce154e7fb10f99361a166468a6c56b9c31aa3 + permissions: + contents: read + id-token: write diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index b2837c4..35afefc 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -8,10 +8,7 @@ on: schedule: - cron: "0 * * * *" -permissions: - contents: read - pages: write - id-token: write +permissions: {} concurrency: group: "pages" @@ -20,11 +17,16 @@ concurrency: jobs: build: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write env: AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }} SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }} ZERION_API_KEY: ${{ secrets.ZERION_API_KEY }} steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: @@ -96,9 +98,14 @@ jobs: deploy: needs: build runs-on: ubuntu-latest + permissions: + id-token: write + pages: write environment: name: github-pages url: ${{ steps.deployment.outputs.page_url }} steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - id: deployment uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4 diff --git a/.github/workflows/scan-github-actions.yml b/.github/workflows/scan-github-actions.yml new file mode 100644 index 0000000..b3b4cd8 --- /dev/null +++ b/.github/workflows/scan-github-actions.yml @@ -0,0 +1,15 @@ +name: Scan GitHub Actions + +"on": + pull_request: + +permissions: {} + +jobs: + scan: + name: Scan GitHub Actions + uses: tempoxyz/gh-actions/.github/workflows/scan-github-actions.yml@6a4184039b7a7537d35ace0badc96764d5a1d4d0 + permissions: + actions: read + contents: read + id-token: write diff --git a/.github/workflows/terraform-cd.yml b/.github/workflows/terraform-cd.yml index 1a103b4..aa2920f 100644 --- a/.github/workflows/terraform-cd.yml +++ b/.github/workflows/terraform-cd.yml @@ -21,16 +21,20 @@ on: required: false default: "" -permissions: - contents: read +permissions: {} jobs: terraform: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write environment: ${{ (inputs.action == 'apply' || inputs.action == 'destroy') && 'production' || 'plan' }} env: AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }} steps: + - name: Secure runner + uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8 - name: Checkout (tarball) timeout-minutes: 5 env: diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..ae3dc4a --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,24 @@ +rules: + template-injection: + ignore: + # Existing benchmark workflows interpolate validated inputs and trusted + # matrix or step outputs into scripts. Keep those files baselined while + # continuing to scan new workflows for template injection. + - benchmark-release.yml + - benchmark-request.yml + - benchmark-run.yml + secrets-outside-env: + ignore: + # These existing automation workflows intentionally consume repository + # secrets without a GitHub deployment environment. + - benchmark-release.yml + - benchmark-run.yml + - docs.yml + secrets-inherit: + ignore: + # The local benchmark runner needs the repository's AWS and Terraform + # secrets and is pinned to the caller's own revision. + - benchmark-request.yml + ref-version-mismatch: + # Tempo's internal actions use immutable pins without matching semver tags. + disable: true