fix(ci): security facade startup failure and ratchet-report on a new baseline - #32
Merged
Merged
Conversation
…baseline security.yml: the `guards` job calls _guards.yml without its own permissions, so it inherits the facade's file-level `contents: read`. _guards' secret-scan job asks for `pull-requests: read` (gitleaks-action lists the PR's commits), which is more than its calling job holds, so GitHub rejects the run before it starts (`startup_failure`, with the reason visible only in the Actions UI). Found adopting v2.2.0 in tech-atlas. The guards job now grants `contents: read` + `pull-requests: read`; the usage example, foundry-init's generated caller and OVERVIEW §13 show the caller granting the same. ratchet-report.yml: `git show "$BASE:$f"` exits 128 when the baseline is not on the base yet (the PR adopting Foundry, or bootstrap's first seed). Under `set -euo pipefail` that failed the job instead of reporting "before: 0".
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two bugs found while adopting v2.2.0 in tech-atlas (CMaintz/tech-atlas#94). Both are small workflow fixes with no interface change, so this is a patch release.
1.
security.ymlfacade: every run ends instartup_failureThe facade's
guardsjob calls_guards.ymlwithout setting its ownpermissions, so it inherits the file-levelcontents: read._guards.yml's Secret scan job asks forpull-requests: read, because gitleaks-action lists the PR's commits. A nested reusable workflow cannot ask for more than its calling job holds, so GitHub rejects the whole run before any job starts. The run shows only "This run likely failed because of a workflow file issue"; the reason is visible only in the Actions UI.Fix: the
guardsjob grantscontents: readandpull-requests: read. The consumer's caller also has to grant these: a repo with the default read-only token has nopull-requests: read. So the usage example insecurity.yml, the caller thatfoundry-init.shgenerates, and OVERVIEW §13 now includepermissions: { contents: read, pull-requests: read }.2.
ratchet-report.ymlfails while a baseline is not on the base yetbefore=$(git show "$BASE:$f" 2>/dev/null | count)runs underset -euo pipefail. When the baseline file does not exist at the base (the PR that adopts Foundry, or bootstrap's first seed PR),git showexits 128, and pipefail +-efail the job instead of reportingbefore: 0. Fix:(git show … || true) | count.Verification
tech-atlas#94 pinned to this branch's commit (
5e16845): thesecurityrun starts and runs guards and SAST (it ended instartup_failureat v2.2.0, run 36547746514), andratchetpasses (it failed with exit 128 at v2.2.0, run 36547746161).After merge
Cut a patch release and move
v2. tech-atlas#94 is pinned to5e16845until then; re-pin it to the release.