Skip to content

ci: pin read-only token permissions and drop persisted checkout credentials (LAB-7516) - #107

Merged
27Bslash6 merged 1 commit into
mainfrom
lab-7516-ci-least-privilege
Oct 3, 2026
Merged

27Bslash6 merged 1 commit into
mainfrom
lab-7516-ci-least-privilege

Conversation

@27Bslash6

Copy link
Copy Markdown
Contributor

ci.yml was the only workflow here without a permissions: block, and its checkouts persisted the job token in .git/config.

  • Workflow-level permissions: contents: read. No job needs more.
  • persist-credentials: false on all three actions/checkout steps (test, wasm32, security). No run: step calls git or gh, so nothing used the persisted credential.

Reason: least-privilege tokens. The file now states its own read-only scope, so a change to the repository default cannot widen it. actionlint and zizmor are clean on the changed file.

Closes LAB-7516

…ntials (LAB-7516)

Least-privilege tokens: the workflow only reads the repository, so it
states contents: read itself instead of inheriting the repository
default, and no checkout leaves a credential in .git/config.
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 3dd7a52b-b467-461b-a5e9-dddf1bff8e94
📥 Commits

Reviewing files that changed from the base of the PR and between dce166b and 1fdbb89.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Security
    • CI test, WebAssembly, and security jobs now have read-only repository access.
    • Git credentials are no longer persisted during checkout.

Walkthrough

The CI workflow now grants read-only contents access. The test, wasm32 and security jobs disable persisted Git credentials in their checkout steps.

Changes

CI workflow permissions

Layer / File(s) Summary
Workflow permissions and checkout settings
.github/workflows/ci.yml
The workflow grants read-only contents access. Checkout steps in the test, wasm32 and security jobs set persist-credentials: false.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 1fdbb

The workflow’s declared jobs appear compatible with the narrower token permissions and disabled credential persistence; no actionable merge risk is identified.

Architecture Summary

Architecture risk: 🔵 Low · up to 1fdbb

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/ci.yml: Added workflow-level contents: read permissions.
  • observed — Modified behavior in .github/workflows/ci.yml: The test job’s checkout now sets persist-credentials: false.
  • observed — Modified behavior in .github/workflows/ci.yml: The wasm32 job’s checkout now sets persist-credentials: false.
  • observed — Modified behavior in .github/workflows/ci.yml: The security job’s checkout now sets persist-credentials: false.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the workflow’s read-only token permissions and removal of persisted checkout credentials.
Description check ✅ Passed The description explains the workflow permission and checkout credential changes and their least-privilege purpose.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kodus-27b

kodus-27b Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@27Bslash6
27Bslash6 merged commit ae2738b into main Oct 3, 2026
33 checks passed
@27Bslash6
27Bslash6 deleted the lab-7516-ci-least-privilege branch October 3, 2026 20:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant