Repository navigation
Feat/security hardening #10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
9738e6e
aa05247
076baae
1ccc539
3ad94b3
aef3e6d
f9356de
0657979
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,85 @@ | ||
| name: CI | ||
|
|
||
| on: | ||
| push: | ||
| branches: [main] | ||
| pull_request: | ||
|
|
||
| # A second push to a PR makes the first run irrelevant. | ||
| concurrency: | ||
| group: ci-${{ github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| env: | ||
| CARGO_TERM_COLOR: always | ||
| RUSTFLAGS: -D warnings | ||
|
|
||
| jobs: | ||
| check: | ||
| name: Format, lint and test | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -e
printf '%s\n' '--- workflow files ---'
git ls-files '.github/workflows/ci.yml'
printf '%s\n' '--- workflow with line numbers ---'
cat -n .github/workflows/ci.yml
printf '%s\n' '--- checkout and git-command references ---'
rg -n -C 3 'actions/checkout|git (clone|fetch|pull|push|config)|github-token|persist-credentials' .github/workflows/ci.ymlRepository: dmaax/mikrotui Length of output: 3928 Disable persisted checkout credentials in all three jobs.
🧰 Tools🪛 zizmor (1.29.0)[warning] 22-22: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) 📍 Affects 1 file
🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
|
|
||
| - uses: dtolnay/rust-toolchain@stable | ||
| with: | ||
| components: rustfmt, clippy | ||
|
|
||
| - uses: Swatinem/rust-cache@v2 | ||
|
|
||
| - name: Check formatting | ||
| run: cargo fmt --all --check | ||
|
|
||
| - name: Clippy | ||
| run: cargo clippy --all-targets --all-features -- -D warnings | ||
|
|
||
| - name: Test (default features) | ||
| run: cargo test --all-targets | ||
|
|
||
| # The keyring backend is behind an optional feature, so the default run | ||
| # never compiles it. | ||
| - name: Test (keyring feature) | ||
| run: cargo test --all-targets --features keyring | ||
|
|
||
| cross-build: | ||
| name: Build ${{ matrix.os }}${{ matrix.features && ' (keyring)' || '' }} | ||
| runs-on: ${{ matrix.os }} | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| os: [macos-latest, windows-latest] | ||
| features: ['', 'keyring'] | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: dtolnay/rust-toolchain@stable | ||
| - uses: Swatinem/rust-cache@v2 | ||
|
|
||
| # Each platform selects a different credential store behind cfg(), so a | ||
| # Linux-only pipeline would never compile the macOS or Windows one. | ||
| - name: Build | ||
| run: cargo build --locked ${{ matrix.features && format('--features {0}', matrix.features) || '' }} | ||
|
|
||
| audit: | ||
| name: Security advisories | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: dtolnay/rust-toolchain@stable | ||
| - uses: taiki-e/install-action@cargo-audit | ||
|
|
||
| # RUSTSEC-2023-0071 — Marvin attack, a timing sidechannel in `rsa`. | ||
| # | ||
| # Ignored because upstream has no fix: the advisory lists `patched = []`, and the | ||
| # crate reaches us transitively through russh, so there is no version to move to. | ||
| # | ||
| # It also does not apply to how MikroTUI uses RSA. The attack recovers a key by | ||
| # timing *private-key* decryption. MikroTUI is a client that authenticates with a | ||
| # password and never holds an RSA private key; RSA appears only to verify the | ||
| # router's host key signature, which is a public-key operation. | ||
| # | ||
| # Revisit if MikroTUI ever gains SSH key authentication. | ||
| # | ||
| # Unmaintained/unsound advisories (fxhash, paste, lru) are reported but do not | ||
| # fail the run: they arrive through ratatui and inquire and are not ours to fix. | ||
| # Any *vulnerability* other than the one ignored here fails the build. | ||
| - run: cargo audit --ignore RUSTSEC-2023-0071 | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: dmaax/mikrotui
Length of output: 3846
🏁 Script executed:
Repository: dmaax/mikrotui
Length of output: 3786
🌐 Web query:
GitHub Actions workflow syntax permissions unspecified permissions set to none contents read pull_request token default permissions official documentation💡 Result:
When using the permissions key in a GitHub Actions workflow or job, if you explicitly define any permission, all other permissions that you do not specify are automatically set to none [1][2][3]. This behavior is a core component of the workflow security model designed to support the principle of least privilege [4][5]. By default, if the permissions key is completely omitted from a workflow, the GITHUB_TOKEN inherits the default permissions configured at the repository or organization level (which may be read-only or read-write) [6][7]. However, as soon as you provide a permissions block, you take full control of the token's scope, and any omitted permissions are effectively disabled [1][8]. For example, if you define only the contents permission, all other possible permissions—such as issues, pull-requests, or packages—will be set to none: permissions: contents: read In this case, the action would have read access to the repository contents, but no access to pull requests or other GitHub features [2]. To grant access to multiple scopes, you must explicitly list each one [4][8].
Citations:
Set explicit read-only
GITHUB_TOKENpermissions.Because this workflow executes pull-request code, an omitted
permissionsblock can inherit broader repository or organization defaults. Add workflow-levelcontents: read; unspecified permissions then becomenone.🤖 Prompt for AI Agents
Source: Linters/SAST tools