Repository navigation
Use read-access GitHub App credentials in zizmor ruleset workflow - #13
Sandhya Adavikolanu (Sandhya1236) wants to merge 2 commits into
Conversation
The intent is to keep PR-time zizmor scanning on the read-access app path used for cross-org/private-repo access, while preserving the current required-workflow gating model. Signed-off-by: Sandhya Adavikolanu <sadaviko@qti.qualcomm.com>
Qualcomm AI ReviewClick to expand Code ReviewReviewed Commits: 22877d9
The intent is to keep PR-time zizmor scanning on the read-access app path used for cross-org/private-repo access, while preserving the current required-workflow gating model. Signed-off-by: Sandhya Adavikolanu sadaviko@qti.qualcomm.com |
…missions Update Address the zizmor github-app finding by explicitly scoping the generated GitHub App token permissions. Change Added the following inputs to the actions/create-github-app-token@v3 step: permission-contents: read permission-actions: read This prevents the token from implicitly inheriting the full installation permission set and aligns the workflow with explicit least-privilege usage. Why The previous version worked functionally, but zizmor correctly flagged that the token request did not explicitly limit permissions in workflow YAML. This update keeps the same intended behavior while making the permission scope explicit for the generated token. Signed-off-by: Sandhya Adavikolanu <sadaviko@qti.qualcomm.com>
Qualcomm AI ReviewClick to expand Code ReviewReviewed commit: 0cc60f2 "Explicitly scope zizmor GitHub App token to contents/actions read permissions Update Change permission-contents: read Why This update keeps the same intended behavior while making the permission scope explicit for the generated token. Signed-off-by: Sandhya Adavikolanu sadaviko@qti.qualcomm.com" Overview: This PR modifies
|
5952628 to
53bb8f6
Compare
53bb8f6 to
a7700ee
Compare
Summary
This PR updates the enterprise zizmor ruleset workflow to use the dedicated read-access GitHub App credentials instead of the previous app credentials.
The intent is to keep PR-time zizmor scanning on the read-access app path used for cross-org/private-repo access, while preserving the current required-workflow gating model.
What changed
In the
actions/create-github-app-token@v3step, the workflow now uses:vars.READ_ACCESS_APP_CLIENT_IDsecrets.READ_ACCESS_APP_PRIVATE_KEYinstead of the previous app credential references.
No other behavior in the workflow is intended to change.
Why
This workflow needs to:
qualcomm/qcom-enterprise-workflowsUsing the dedicated read-access app credentials keeps that access path explicit and aligned with the intended least-privilege model for this ruleset workflow.
Validation / current rollout status
Validation completed so far:
impostor-commitissueFollow-up
Still need to verify ruleset scope/application in each org so the required workflow is enforced everywhere intended.
Once ruleset targeting is confirmed, the remaining rollout risk should mainly be configuration/scope verification rather than app credential setup.
This change is validated for the tested cross-org stg/zephyr path. Follow-up remains to confirm ruleset targeting in each org and to further validate/research fork PR behavior under the required workflow setup.
https://github.com/qualcomm-linux-stg/Sandhya-Test_repo/actions/runs/35256425000/job/105321098357?pr=14