Skip to content

Increase lint-and-test workflow security and tighten permissions - #753

Merged
Exairnous merged 1 commit into
Hubs-Foundation:masterfrom
Exairnous:secure-lint-and-test-workflow
Jul 3, 2026
Merged

Exairnous merged 1 commit into
Hubs-Foundation:masterfrom
Exairnous:secure-lint-and-test-workflow

Conversation

@Exairnous

@Exairnous Exairnous commented Jun 29, 2026 •

Copy link
Copy Markdown
Member

What?

Sets permissions to none, pins calls to external actions to specific commits, and prevents credentials from actions/checkout from persisting.

Why?

To minimize the chance of the workflow being hacked or vulnerable to a supply chain hack (pinning the external action calls helps with this), and in preparation to globally restrict permissions for all Hubs Foundation workflows.

Examples

N/A

How to test

  1. Push the changes to your fork.
  2. Run the workflow (if it doesn't run automatically).
  3. See that it works normally.

To verify that all the Zizmor issues have been addressed, run the following command from the repository folder and see that Zizmor reports no issues (that we care about) for the lint-and-test workflow.

docker run --rm --name zizmor -v .:/usr/repo ghcr.io/zizmorcore/zizmor --fix=all /usr/repo

Documentation of functionality

This doesn't change the functionality of the workflow, so no documentation update is needed.

Known limitations

This doesn't update any of the external workflow versions. I feel it is out of scope for this PR and can/should be done along with all the others in further PRs when addressing GitHub's required update to use Node 24+.

Alternative implementations considered

None.

Open questions

None.

Additional details or related context

These security improvements were advised by the Zizmor tool and GitHubSecurityLab/actions-permissions/monitor@bf82d13b9b10051d224345ab9184f5ede0a94289 #v1 Beta 9

Part of Hubs-Foundation/.github#13

What: sets permissions to none, pins calls to external actions to specific commits, and prevents credentials from actions/checkout from persisting.

Why: to minimize the chance of the workflow being hacked or vulnerable to a supply chain hack (pinning the external action calls helps with this), and in preparation to globally restrict permissions for all Hubs Foundation workflows.

Note: these security improvements were advised by the Zizmor tool and `GitHubSecurityLab/actions-permissions/monitor@bf82d13b9b10051d224345ab9184f5ede0a94289 #v1 Beta 9`
@github-actions

Copy link
Copy Markdown

Thank you for the pull request.

ROADMAP STATUS: This pull request isn't currently on any roadmap. Updates will be conveyed here as its place on/off a roadmap changes.

You can view the roadmaps here: Roadmaps Google Drive folder.

For more information on how the roadmaps work, see our roadmaps policy on GitHub.

@Exairnous Exairnous added the Roadmap: Programming Indicates that this issue/pull request is on the Programming Team roadmap label Jun 29, 2026

@DougReeder DougReeder left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I’m unable to double-check the workflow at the moment, but this looks good to me.

@Exairnous

Copy link
Copy Markdown
Member Author

@DougReeder Thank you. Merging.

@Exairnous
Exairnous merged commit e4367dc into Hubs-Foundation:master Jul 3, 2026
2 checks passed
Exairnous added a commit that referenced this pull request Jul 12, 2026
Increase lint-and-test workflow security and tighten permissions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Roadmap: Programming Indicates that this issue/pull request is on the Programming Team roadmap

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants