From dd604f75a3e8ddcc8e35c92d5b14bbe4e6b6003c Mon Sep 17 00:00:00 2001 From: Sean Huh Date: Fri, 2 Oct 2026 21:26:35 +0000 Subject: [PATCH 1/2] Drop repo/bazel cache, prune disk cache entries --- .github/workflows/workflow.yml | 30 ++++++++++++++++++------------ 1 file changed, 18 insertions(+), 12 deletions(-) diff --git a/.github/workflows/workflow.yml b/.github/workflows/workflow.yml index 8a34af31c..cbd4fec6b 100644 --- a/.github/workflows/workflow.yml +++ b/.github/workflows/workflow.yml @@ -24,15 +24,13 @@ jobs: - run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}." - name: Check out repository code uses: actions/checkout@v6 + - name: Mark job start + run: touch "$RUNNER_TEMP/job-start" - name: Setup Bazel uses: bazel-contrib/setup-bazel@0.18.0 with: - # Avoid downloading Bazel every time. - bazelisk-cache: true # Store build cache per workflow. disk-cache: ${{ github.workflow }}-${{ github.job }} - # Share repository cache between workflows. - repository-cache: true # Prevent PRs from polluting cache cache-save: ${{ github.event_name != 'pull_request' }} - name: Bazel Output Version @@ -43,6 +41,13 @@ jobs: run: .github/workflows/unwanted_deps.sh - name: Cross-artifact Duplicate Classes Check run: .github/workflows/cross_artifact_dependencies_check.sh + - name: Prune disk cache entries not used by this job + # Bazel bumps mtimes on use; drop stale entries so the saved cache doesn't grow unbounded. + if: github.event_name != 'pull_request' + run: | + du -sh ~/.cache/bazel-disk + find ~/.cache/bazel-disk -type f ! -newer "$RUNNER_TEMP/job-start" -delete + du -sh ~/.cache/bazel-disk - run: echo "🍏 This job's status is ${{ job.status }}." Bazel-Tests: @@ -54,15 +59,13 @@ jobs: - run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}." - name: Check out repository code uses: actions/checkout@v6 + - name: Mark job start + run: touch "$RUNNER_TEMP/job-start" - name: Setup Bazel uses: bazel-contrib/setup-bazel@0.18.0 with: - # Avoid downloading Bazel every time. - bazelisk-cache: true # Store build cache per workflow. disk-cache: ${{ github.workflow }}-${{ github.job }} - # Share repository cache between workflows. - repository-cache: true # Prevent PRs from polluting cache cache-save: ${{ github.event_name != 'pull_request' }} - name: Bazel Output Version @@ -71,6 +74,13 @@ jobs: # Exclude codelab exercises as they are intentionally made to fail # Exclude maven conformance tests. They are only executed when there's version change. run: bazelisk test ... --deleted_packages=//codelab/src/test/codelab --test_output=errors --test_tag_filters=-conformance_maven --build_tag_filters=-conformance_maven + - name: Prune disk cache entries not used by this job + # Bazel bumps mtimes on use; drop stale entries so the saved cache doesn't grow unbounded. + if: github.event_name != 'pull_request' + run: | + du -sh ~/.cache/bazel-disk + find ~/.cache/bazel-disk -type f ! -newer "$RUNNER_TEMP/job-start" -delete + du -sh ~/.cache/bazel-disk - run: echo "🍏 This job's status is ${{ job.status }}." # -- Start of Maven Conformance Tests (Ran only when there's version changes) -- @@ -92,12 +102,8 @@ jobs: if: steps.changed_file.outputs.any_changed == 'true' uses: bazel-contrib/setup-bazel@0.18.0 with: - # Avoid downloading Bazel every time. - bazelisk-cache: true # Store build cache per workflow. disk-cache: ${{ github.workflow }}-${{ github.job }} - # Share repository cache between workflows. - repository-cache: true # Never write to the cache, strictly read-only cache-save: false - name: Verify Version Consistency From 429d0173444fb37f3540a0b7c1ce148c70d1e0c5 Mon Sep 17 00:00:00 2001 From: Sean Huh Date: Fri, 2 Oct 2026 22:58:57 +0000 Subject: [PATCH 2/2] Address security findings --- .github/workflows/workflow.yml | 39 +++++++++++++++++++++++----------- 1 file changed, 27 insertions(+), 12 deletions(-) diff --git a/.github/workflows/workflow.yml b/.github/workflows/workflow.yml index cbd4fec6b..db05f702c 100644 --- a/.github/workflows/workflow.yml +++ b/.github/workflows/workflow.yml @@ -14,6 +14,9 @@ concurrency: group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} cancel-in-progress: true +permissions: + contents: read + jobs: Bazel-Build-Java8: runs-on: ubuntu-latest @@ -21,13 +24,15 @@ jobs: steps: - run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event." - run: echo "🐧 Job is running on a ${{ runner.os }} server!" - - run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}." + - run: echo "🔎 The name of your branch is ${GITHUB_REF} and your repository is ${GITHUB_REPOSITORY}." - name: Check out repository code - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 + with: + persist-credentials: false - name: Mark job start run: touch "$RUNNER_TEMP/job-start" - name: Setup Bazel - uses: bazel-contrib/setup-bazel@0.18.0 + uses: bazel-contrib/setup-bazel@083175551ceeceebc757ebee2127fde78840ca77 # 0.18.0 with: # Store build cache per workflow. disk-cache: ${{ github.workflow }}-${{ github.job }} @@ -48,7 +53,9 @@ jobs: du -sh ~/.cache/bazel-disk find ~/.cache/bazel-disk -type f ! -newer "$RUNNER_TEMP/job-start" -delete du -sh ~/.cache/bazel-disk - - run: echo "🍏 This job's status is ${{ job.status }}." + - run: echo "🍏 This job's status is ${JOB_STATUS}." + env: + JOB_STATUS: ${{ job.status }} Bazel-Tests: runs-on: ubuntu-latest @@ -56,13 +63,15 @@ jobs: steps: - run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event." - run: echo "🐧 Job is running on a ${{ runner.os }} server!" - - run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}." + - run: echo "🔎 The name of your branch is ${GITHUB_REF} and your repository is ${GITHUB_REPOSITORY}." - name: Check out repository code - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 + with: + persist-credentials: false - name: Mark job start run: touch "$RUNNER_TEMP/job-start" - name: Setup Bazel - uses: bazel-contrib/setup-bazel@0.18.0 + uses: bazel-contrib/setup-bazel@083175551ceeceebc757ebee2127fde78840ca77 # 0.18.0 with: # Store build cache per workflow. disk-cache: ${{ github.workflow }}-${{ github.job }} @@ -81,7 +90,9 @@ jobs: du -sh ~/.cache/bazel-disk find ~/.cache/bazel-disk -type f ! -newer "$RUNNER_TEMP/job-start" -delete du -sh ~/.cache/bazel-disk - - run: echo "🍏 This job's status is ${{ job.status }}." + - run: echo "🍏 This job's status is ${JOB_STATUS}." + env: + JOB_STATUS: ${{ job.status }} # -- Start of Maven Conformance Tests (Ran only when there's version changes) -- Maven-Conformance: @@ -90,17 +101,21 @@ jobs: steps: - run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event." - run: echo "🐧 Job is running on a ${{ runner.os }} server!" - - run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}." + - run: echo "🔎 The name of your branch is ${GITHUB_REF} and your repository is ${GITHUB_REPOSITORY}." - name: Check out repository code - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 + with: + # Full history so changed-files doesn't need credentials to fetch more. + fetch-depth: 0 + persist-credentials: false - name: Get changed files id: changed_file - uses: tj-actions/changed-files@v47 + uses: tj-actions/changed-files@24d32ffd492484c1d75e0c0b894501ddb9d30d62 # v47.0.0 with: files: publish/cel_version.bzl - name: Setup Bazel if: steps.changed_file.outputs.any_changed == 'true' - uses: bazel-contrib/setup-bazel@0.18.0 + uses: bazel-contrib/setup-bazel@083175551ceeceebc757ebee2127fde78840ca77 # 0.18.0 with: # Store build cache per workflow. disk-cache: ${{ github.workflow }}-${{ github.job }}