Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release-24.05] Workflows security fix #351461

Merged

Conversation

infinisil
Copy link
Member

Manual backport of #351446 and #351451


Add a 👍 reaction to pull requests you find important.

Co-Authored-By: 13x1 <[email protected]>
Co-Authored-By: basti564 <[email protected]>
(cherry picked from commit 59aee1c)
read-all permissions gives access to e.g. security-events, which these
don't need, and can easily lead to leaks

Co-Authored-By: 13x1 <[email protected]>
Co-Authored-By: basti564 <[email protected]>
(cherry picked from commit 6b8ce4a)
In the previous two commits, security issues with these workflows were
fixed. In order for these to not be exploitable for PRs to branches that
don't have the fixes yet (including read-only branches like
nixos-unstable), these workflows are renamed, so that the old ones can
be turned off manually via GitHub interface.

Co-Authored-By: 13x1 <[email protected]>
Co-Authored-By: basti564 <[email protected]>
(cherry picked from commit 5bbbc3a)
@infinisil infinisil requested a review from Mic92 October 26, 2024 14:59
@yorickvP yorickvP merged commit d89c30c into NixOS:release-24.05 Oct 26, 2024
7 of 8 checks passed
@infinisil infinisil deleted the backport-workflows-security-fix branch October 26, 2024 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants