Skip to content

Use read-access GitHub App credentials in zizmor ruleset workflow - #13

Open
Sandhya Adavikolanu (Sandhya1236) wants to merge 2 commits into
qualcomm:mainfrom
Sandhya1236:Update-zizmor-scan.yml-1
Open

Sandhya Adavikolanu (Sandhya1236) wants to merge 2 commits into
qualcomm:mainfrom
Sandhya1236:Update-zizmor-scan.yml-1

Conversation

@Sandhya1236

Copy link
Copy Markdown

Summary

This PR updates the enterprise zizmor ruleset workflow to use the dedicated read-access GitHub App credentials instead of the previous app credentials.

The intent is to keep PR-time zizmor scanning on the read-access app path used for cross-org/private-repo access, while preserving the current required-workflow gating model.

What changed

In the actions/create-github-app-token@v3 step, the workflow now uses:

  • vars.READ_ACCESS_APP_CLIENT_ID
  • secrets.READ_ACCESS_APP_PRIVATE_KEY

instead of the previous app credential references.

No other behavior in the workflow is intended to change.

Why

This workflow needs to:

  • check out the repository under audit
  • fetch the pinned central zizmor policy from qualcomm/qcom-enterprise-workflows
  • allow zizmor online audits / resolution in scenarios involving private resources across org boundaries

Using the dedicated read-access app credentials keeps that access path explicit and aligned with the intended least-privilege model for this ruleset workflow.

Validation / current rollout status

Validation completed so far:

  • Verified the staging-to-zephyr cross-org case in the test setup
  • Confirmed the workflow path works with the dedicated app credential references
  • Confirmed the required org variable and secret are configured
  • Confirmed the app is installed in all five orgs
  • Set the app repository scope to all repositories for now
  • Confirmed the tested scenario no longer hits the earlier impostor-commit issue

Follow-up

Still need to verify ruleset scope/application in each org so the required workflow is enforced everywhere intended.

Once ruleset targeting is confirmed, the remaining rollout risk should mainly be configuration/scope verification rather than app credential setup.

This change is validated for the tested cross-org stg/zephyr path. Follow-up remains to confirm ruleset targeting in each org and to further validate/research fork PR behavior under the required workflow setup.
https://github.com/qualcomm-linux-stg/Sandhya-Test_repo/actions/runs/35256425000/job/105321098357?pr=14

The intent is to keep PR-time zizmor scanning on the read-access app path used for cross-org/private-repo access, while preserving the current required-workflow gating model.

Signed-off-by: Sandhya Adavikolanu  <sadaviko@qti.qualcomm.com>
Comment thread .github/workflows/zizmor-scan.yml Fixed
@qualcomm-ai-code-review-assistant

Copy link
Copy Markdown

Qualcomm AI Review

Click to expand Code Review
Reviewed Commits: 22877d9
  • 22877d9: Use read-access GitHub App credentials in zizmor ruleset workflow

The intent is to keep PR-time zizmor scanning on the read-access app path used for cross-org/private-repo access, while preserving the current required-workflow gating model.

Signed-off-by: Sandhya Adavikolanu sadaviko@qti.qualcomm.com


⚠️ This review was generated using AI assistance. Please verify all suggestions before applying.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Qualcomm AI Review

…missions

Update
Address the zizmor github-app finding by explicitly scoping the generated GitHub App token permissions.

Change
Added the following inputs to the actions/create-github-app-token@v3 step:

permission-contents: read
permission-actions: read
This prevents the token from implicitly inheriting the full installation permission set and aligns the workflow with explicit least-privilege usage.

Why
The previous version worked functionally, but zizmor correctly flagged that the token request did not explicitly limit permissions in workflow YAML.

This update keeps the same intended behavior while making the permission scope explicit for the generated token.

Signed-off-by: Sandhya Adavikolanu  <sadaviko@qti.qualcomm.com>
@qualcomm-ai-code-review-assistant

Copy link
Copy Markdown

Qualcomm AI Review

Click to expand Code Review

Reviewed commit: 0cc60f2 "Explicitly scope zizmor GitHub App token to contents/actions read permissions

Update
Address the zizmor github-app finding by explicitly scoping the generated GitHub App token permissions.

Change
Added the following inputs to the actions/create-github-app-token@v3 step:

permission-contents: read
permission-actions: read
This prevents the token from implicitly inheriting the full installation permission set and aligns the workflow with explicit least-privilege usage.

Why
The previous version worked functionally, but zizmor correctly flagged that the token request did not explicitly limit permissions in workflow YAML.

This update keeps the same intended behavior while making the permission scope explicit for the generated token.

Signed-off-by: Sandhya Adavikolanu sadaviko@qti.qualcomm.com"

Overview: This PR modifies .github/workflows/zizmor-scan.yml to add explicit permission-contents: read and permission-actions: read inputs to the actions/create-github-app-token@v3 step, scoping down the GitHub App token used throughout the workflow.

File Lines Changed Issues Found Highest Severity
.github/workflows/zizmor-scan.yml +2 (lines 107-108) 0 None

⚠️ This review was generated using AI assistance. Please verify all suggestions before applying.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Qualcomm AI Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants