Repository navigation
ci: declare least-privilege token scope for the estate audit workflow - #92
Conversation
main-estate-audit.yml was the only workflow in .github/workflows/ with no `permissions:` block, so its GITHUB_TOKEN inherited the repository-default scopes. Every one of its 27 steps is a shell gate over the checked-out tree; none of the cicd-suite composite actions take a token or call the GitHub API. `contents: read` is therefore the complete grant, and declaring it brings this file in line with the other 15 workflows in the directory. Verified with the official GitHub Actions workflow JSON schema (16/16 pass) and actionlint 2.0.6 (no new findings). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Controlled reproduction:
|
| workflow | #91 | #92 |
|---|---|---|
| Selected Package Tests | startup_failure | startup_failure |
| Repository Static Checks | startup_failure | startup_failure |
| Secret Scanner | startup_failure | startup_failure |
| CodeQL Security Analysis | startup_failure | startup_failure |
| Hypatia Security Scan | startup_failure | startup_failure |
| Governance | startup_failure | startup_failure |
| Dependabot Auto-Merge | startup_failure | startup_failure |
| Central Estate CI/CD Audit | startup_failure | startup_failure |
8 of 8 eligible pull_request workflows failed — a 100% failure rate, with a
diff that cannot explain it. (The 9th on #91, panic-attack / unified-api-adapter, is paths:-gated on
connectors/proven-nesy-solver-api/zig/**, which this PR does not touch, so it
correctly did not trigger.)
Additional evidence that no job ever ran:
total_count: 0for all 8 check suites, and0for
/actions/runs/{id}/jobs?filter=all.started_at: nullandcompleted_at: nullon all 8 suites.- No check-run records on the head SHA — only the third-party apps
(CodeFactor, GitGuardian, Semgrep) produced check-runs at all.
The two most conclusive data points are Repository Static Checks and
Selected Package Tests. Both are trivial — actions/checkout, bash -n
over shell scripts, and the two source-pattern suites that pass locally
(68/0/4 and 62/0/0). They succeeded on the push to main three minutes
after #91's identical runs startup-failed, and they startup-failed here. A
file that only runs bash -n cannot be rejected by an Actions admission
layer.
Reruns
POST /actions/runs/{id}/rerun → 403 Resource not accessible by integration.
/actions/permissions and /branches/main/protection → 403 too. The app
token lacks actions: write; this is a token-scope limit, not a property of
the runs.
Recommended next step
This should go to GitHub Support as an Actions admission failure on this
repository, with the table above as the reproduction. I am not treating it as a
content defect and have deliberately not changed workflow content to chase it.
Follow-up to #91. #91 is already merged, so this is a separate PR, and it is
not being merged by me — see "Merge authorization" below.
Why this is only a one-line-class change
Recon of the nine
startup_failureruns on #91 concluded that no workflowfile in this repository is defective, so there was nothing to repair there.
The one real, provable workflow/permissions defect found is a missing
GITHUB_TOKENscope declaration.The change
main-estate-audit.ymlwas the only workflow in.github/workflows/with nopermissions:block, so its token inherited the repository-default scopes.All 27 steps are shell gates over the checked-out working tree. I read the
action.ymlof the cicd-suite composite actions it calls (at the pinned5a10b72e…) and none of them take a token or call the GitHub API. Socontents: readis the complete grant. This brings the file in line with theother 15 workflows in the directory.
Verification
actionlint2.0.6 (WASM build, since the release binary host is blocked inthis sandbox): no new findings.
bash -nover all 10 shell scripts: pass.tests/source_smoke_test.sh: PASS=68 FAIL=0 SKIP=4 (rc 0).tests/aspect/security_test.sh: PASS=62 FAIL=0 SKIP=0 (rc 0).tests/binding_inventory.sh: rc 0.Diagnostics for the maintainer (not fixed here — see PR description thread)
startup_failureon all nine Audit evidence claims and disable unsupported product paths #91pull_requestruns is not a contentdefect. Every run has
total_count: 0jobs (also withfilter=all) andno check-run, so no YAML, action, or permission was ever evaluated. The
same workflow blobs (
git rev-parseidentical) ran normally three minuteslater on the merge to
main. Repo-wide there are 243startup_failureruns across
push,pull_request, andschedule, and in mixed bursts thesame file both succeeds and startup-fails (2026-09-20T00:09:03Z: Mirror +
Secret Scanner succeeded while 8 others failed). This is an Actions
admission/service failure and needs escalation to GitHub Support, not a
content change.
un-rerunnable.
POST /actions/runs/{id}/rerunreturns403 Resource not accessible by integration;/actions/permissionsand/branches/main/protectionreturn 403 as well. The app token is missingactions: write.main, unrelated to Audit evidence claims and disable unsupported product paths #91. I reproduced thecode-hygiene gate locally (identical 19 findings on ci: retire the dead A2ML validation gate #90's tree and on
Audit evidence claims and disable unsupported product paths #91's). They are 6 OSPF
STUBLSA-type constants inbindings/*/ospf.*(domain false positives), 2 self-matches in
scripts/maintenance/run-maintenance.sh, and 11 genuine untrackedTODO(scope):markers inprotocols/*. Resolving or allowlisting those isa governance decision, so I did not touch it.
main(annotations, not logs — log blobs arebehind hosts this sandbox cannot reach): Instant Sync =
Bad credentials;Hypatia =
Path does not exist: hypatia.sarif; panic-attack = exit 128with
/tmp/panic-findings.jsonnever written.Toolchain limits, stated plainly
idris2andzigcould not be run here, so no compiler-backed evidence isproduced by this PR.
ziglang.organd the apt mirrors are unreachable fromthis sandbox, and the only Zig obtainable via the npm registry is 0.14.0-dev,
which fails on
std.Build.addLibrary(a 0.15 API, the version CI pins). TheIdris2 bootstrap needs Chez Scheme and
gmp.h, and neither apt norftp.gnu.orgis reachable.tests/e2e.shtherefore did not run; thesource-pattern suites above are all that did.
Merge authorization
Not merging. #91 was merged by
hyperpolymathat 2026-09-27T04:42:30Z, and Ihave no authorization to merge this follow-up myself. It should be merged by
a maintainer after review.