Skip to content

fix: replace secrets: inherit with explicit secret mappings in CI/CD workflows - #213

Merged
walteck merged 1 commit into
mainfrom
chwa1-ENG-1060-resolve-static-analysis-finding
Apr 20, 2026
Merged

walteck merged 1 commit into
mainfrom
chwa1-ENG-1060-resolve-static-analysis-finding

Conversation

@walteck

@walteck walteck commented Apr 10, 2026

Copy link
Copy Markdown
Contributor

Description

Replace secrets: inherit with explicit secret mappings in the CI/CD pull request workflow and add corresponding secrets: declarations to the reusable stage workflows.

  • cicd-1-pull-request.yaml: commit-stage now passes only the four IDP_AWS_REPORT_UPLOAD_* secrets; test-stage now passes only SONAR_TOKEN; build-stage and acceptance-stage no longer pass any secrets as none are required
  • stage-1-commit.yaml: added secrets: block to on.workflow_call declaring the four IDP_AWS_REPORT_UPLOAD_* secrets
  • stage-2-test.yaml: added secrets: block to on.workflow_call declaring SONAR_TOKEN

Context

SonarCloud flagged the use of secrets: inherit in .github/workflows/cicd-1-pull-request.yaml (lines 81, 94, 108, and 122) as a security risk.

When secrets: inherit is used to call a reusable workflow, all repository secrets are made available to that workflow, violating the principle of least privilege. By replacing it with explicit secret mappings, each reusable workflow receives only the specific secrets it requires, reducing the blast radius of any potential secret exposure.

Type of changes

  • Refactoring (non-breaking change)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would change existing functionality)
  • Bug fix (non-breaking change which fixes an issue)

Checklist

  • I am familiar with the contributing guidelines
  • I have followed the code style of the project
  • I have added tests to cover my changes
  • I have updated the documentation accordingly
  • This PR is a result of pair or mob programming

Sensitive Information Declaration

To ensure the utmost confidentiality and protect your and others privacy, we kindly ask you to NOT including PII (Personal Identifiable Information) / PID (Personal Identifiable Data) or any other sensitive data in this PR (Pull Request) and the codebase changes. We will remove any PR that do contain any sensitive information. We really appreciate your cooperation in this matter.

  • I confirm that neither PII/PID nor sensitive data are included in this PR and the codebase changes.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens GitHub Actions reusable-workflow secret handling by removing secrets: inherit and explicitly passing only the secrets each stage needs, aligning the CI/CD pull request pipeline with least-privilege principles and addressing the SonarCloud finding.

Changes:

  • Replaced secrets: inherit with explicit secret mappings when calling reusable stage workflows from the pull request pipeline.
  • Declared required/optional on.workflow_call.secrets in reusable workflows so callers can only pass approved secrets.
  • Stopped passing secrets to stages that don’t use them (build and acceptance).

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
.github/workflows/cicd-1-pull-request.yaml Replaces secrets: inherit with explicit secret mappings for commit/test stages; removes secret passing for build/acceptance.
.github/workflows/stage-1-commit.yaml Declares the four IDP_AWS_REPORT_UPLOAD_* secrets for workflow_call (optional).
.github/workflows/stage-2-test.yaml Declares SONAR_TOKEN for workflow_call (required).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@stefaniuk stefaniuk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants