From b45b5dc2b5ac67b9bc2cc23b11ea011115ffc2cd Mon Sep 17 00:00:00 2001 From: warden Date: Tue, 15 Sep 2026 12:46:48 +0000 Subject: [PATCH 1/2] fix(ci): stop persisting a write-scoped git credential through npm ci The release job declares `contents: write`, which overrides this repo's read-only default workflow permission, so actions/checkout's default persisted credential was write-scoped and stayed live in .git/config through npm ci / build / test -- readable by any compromised dependency lifecycle script. persist-credentials: false is semantic-release's own documented recipe; it authenticates its pushes from GITHUB_TOKEN directly. Part of the CWE-250 pattern-set fix across WYRE-AI/node-*. Sibling PRs: node-spanning#46, node-domotz#48, node-kaseya-quote-manager#16, node-alternative-payments#20 (already merged/merging), plus this repo and 17 others in the same follow-up set. --- .github/workflows/release.yml | 9 +++++++++ CHANGELOG.md | 3 +++ 2 files changed, 12 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f8862a4..9ab9afc 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -56,6 +56,15 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + # The release job declares `contents: write`, which overrides this repo's + # read-only default workflow permission -- so the checkout's default + # persisted credential is WRITE-scoped and stays live in .git/config + # through `npm ci` below. A compromised dependency lifecycle script + # could read it off disk and push. semantic-release authenticates its + # own pushes from GITHUB_TOKEN, so it does not need the persisted + # credential; `persist-credentials: false` is semantic-release's own + # documented GitHub Actions recipe. (CWE-250) + persist-credentials: false - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 diff --git a/CHANGELOG.md b/CHANGELOG.md index 0315301..89e8784 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -43,6 +43,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] ### Added + +- **Release workflow no longer persists a write-scoped git credential across `npm ci`.** The release job declares `contents: write`, which overrides this repo's read-only default workflow permission, so `actions/checkout`'s default persisted credential was write-scoped and lived in `.git/config` through dependency install, build and test — readable by any compromised dependency lifecycle script. `persist-credentials: false` is semantic-release's own documented GitHub Actions recipe; it authenticates its pushes from `GITHUB_TOKEN` directly and never needed the persisted credential. (CWE-250) + - Initial scaffold of `@wyre-technology/node-iqms` SDK. - Oracle read driver with parameterized query layer for work orders, inventory, BOMs, sales orders, purchase orders, schedule, and quality entities. Queries are marked From 8e598edb86d7a417f2f8528f6393469c6868346d Mon Sep 17 00:00:00 2001 From: wyre-agent-fleet Date: Wed, 16 Sep 2026 12:46:15 +0000 Subject: [PATCH 2/2] fix: correct CHANGELOG release-job wording per CodeRabbit review Refer to the release job rather than the release workflow, drop the tests reference (tests run only in the separate needs: test job, not the release job itself), and scope the credential-protection claim to the release job's dependency-install and build steps. --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 89e8784..8b4a042 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -44,7 +44,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Added -- **Release workflow no longer persists a write-scoped git credential across `npm ci`.** The release job declares `contents: write`, which overrides this repo's read-only default workflow permission, so `actions/checkout`'s default persisted credential was write-scoped and lived in `.git/config` through dependency install, build and test — readable by any compromised dependency lifecycle script. `persist-credentials: false` is semantic-release's own documented GitHub Actions recipe; it authenticates its pushes from `GITHUB_TOKEN` directly and never needed the persisted credential. (CWE-250) +- **The release job no longer persists a write-scoped git credential across `npm ci`.** It declares `contents: write`, which overrides this repo's read-only default workflow permission, so `actions/checkout`'s default persisted credential was write-scoped and lived in `.git/config` through the release job's dependency install and build steps — readable by any compromised dependency lifecycle script. `persist-credentials: false` is semantic-release's own documented GitHub Actions recipe; it authenticates its pushes from `GITHUB_TOKEN` directly and never needed the persisted credential. (CWE-250) - Initial scaffold of `@wyre-technology/node-iqms` SDK. - Oracle read driver with parameterized query layer for work orders, inventory, BOMs,