From 6e59207d6be682eb1f07210f4ae99d0698609801 Mon Sep 17 00:00:00 2001 From: warden Date: Tue, 15 Sep 2026 12:47:18 +0000 Subject: [PATCH] fix(ci): stop persisting a write-scoped git credential through npm ci The release job declares `contents: write`, which overrides this repo's read-only default workflow permission, so actions/checkout's default persisted credential was write-scoped and stayed live in .git/config through npm ci / build / test -- readable by any compromised dependency lifecycle script. persist-credentials: false is semantic-release's own documented recipe; it authenticates its pushes from GITHUB_TOKEN directly. Part of the CWE-250 pattern-set fix across WYRE-AI/node-*. Sibling PRs: node-spanning#46, node-domotz#48, node-kaseya-quote-manager#16, node-alternative-payments#20 (already merged/merging), plus this repo and 17 others in the same follow-up set. --- .github/workflows/release.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 1d6188b..f684ce5 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -34,6 +34,15 @@ jobs: - uses: actions/checkout@v7 with: fetch-depth: 0 + # The release job declares `contents: write`, which overrides this repo's + # read-only default workflow permission -- so the checkout's default + # persisted credential is WRITE-scoped and stays live in .git/config + # through `npm ci` below. A compromised dependency lifecycle script + # could read it off disk and push. semantic-release authenticates its + # own pushes from GITHUB_TOKEN, so it does not need the persisted + # credential; `persist-credentials: false` is semantic-release's own + # documented GitHub Actions recipe. (CWE-250) + persist-credentials: false - uses: actions/setup-node@v7 with: node-version: 22