Skip to content

fix(security): several codeql fixes - #3475

Open
taciturnaxolotl wants to merge 2 commits into
mainfrom
codeql
Open

fix(security): several codeql fixes#3475
taciturnaxolotl wants to merge 2 commits into
mainfrom
codeql

Conversation

@taciturnaxolotl

Copy link
Copy Markdown
Member

The write, edit, and multiedit tools all called os.MkdirAll before showing the permission prompt, so a denied request still left empty directories behind. An agent could mkdir -p anywhere on the machine with no consent. Move MkdirAll to just before os.WriteFile, matching the ordering the download tool already uses.

Also added proper permission scoping on all the github workflows to avoid excessive permissions

write, edit, and multiedit called os.MkdirAll before showing the
permission prompt, so a denied request still left empty directories
behind. An agent could mkdir -p anywhere on the machine with no
consent. Move MkdirAll to just before os.WriteFile, matching the
ordering the download tool already uses.
Comment thread internal/agent/tools/edit.go Dismissed
Comment thread internal/agent/tools/multiedit.go Dismissed
Comment thread internal/agent/tools/write.go Dismissed
lint, nightly, release, and schema-update ran with the repo default
write-all token because they had no permissions block. Add explicit
least-privilege scopes: contents read for lint and schema-update (the
latter commits via PAT, not GITHUB_TOKEN). For the goreleaser-driven
release and nightly jobs, grant contents/packages write plus id-token
write (OIDC for cosign signing) to match what the reusable meta
workflows declare, plus actions read for the nightly check job.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants