Repository navigation
ci: Harden semantic PR check against pull_request_target risks - #2741
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe semantic PR workflow documents ChangesSemantic PR workflow security
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
5c92ac9 to
788c580
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/semantic-pr-check.yml:
- Around line 4-5: Update the explanatory comment in the pull_request_target
workflow to state that it uses the workflow definition from the base
repository’s default branch, replacing the inaccurate “base branch” wording
without changing the workflow behavior.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 9c9d4a72-3755-488b-af49-f1440ce30b5a
📒 Files selected for processing (1)
.github/workflows/semantic-pr-check.yml
|
So, while I think we all agree that |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2741 +/- ##
=======================================
Coverage 98.28% 98.28%
=======================================
Files 65 65
Lines 4312 4312
Branches 467 467
=======================================
Hits 4238 4238
Misses 46 46
Partials 28 28
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
788c580 to
36e7594
Compare
36e7594 to
1264e41
Compare
|
@agriyakhetarpal pointed out on the Scientific Python Discord that
|
* While the pull_request_target trigger is required by
amannn/action-semantic-pull-request to validate PRs from forks with the
workflow definition taken from the default branch, its elevated
GITHUB_TOKEN is hardened.
- Pin amannn/action-semantic-pull-request to the full commit SHA so a
moved tag can't run unreviewed code with the elevated token.
- Removed 'statuses: write' job permission as unused in v6+ of the action,
and so use 'pull-requests: read'.
- Set the workflow-level default permissions to deny-all ('{}'). The only
job declares its own permissions block, so this only guards any
future jobs added without one.
- Note why the trigger is acceptable here (no checkout or execution of
PR-controlled content) and that future revisions must not change this.
* GitHub actions have also hardened pull_request_target in general so that it
is no longer a direct security threat.
- https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/
Assisted-by: ClaudeCode:claude-fable-5
1264e41 to
1f841a7
Compare
Description
pull_request_target triggeris required by https://github.com/amannn/action-semantic-pull-request to validate PRs from forks with the workflow definition taken from the default branch, its elevatedGITHUB_TOKENis hardened.amannn/action-semantic-pull-requestto the full commit SHA so a moved tag can't run unreviewed code with the elevated token.'statuses: write'job permission as unused inv6+of the action, and so use'pull-requests: read'.'{}'). The only job declares its own permissions block, so this only guards any future jobs added without one.is no longer a direct security threat.
Assisted-by: ClaudeCode:claude-fable-5
Checklist Before Requesting Reviewer
Before Merging
For the PR Assignees:
Summary by CodeRabbit
Summary by CodeRabbit