diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7b31302..d4ff3fc 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,13 +1,19 @@ version: 2 +# A release is proposed only once it is a week old: a compromised or broken release is usually pulled +# within days. The cooldown holds back version updates only; security updates still come at once. updates: - package-ecosystem: "github-actions" directory: "/" schedule: interval: "weekly" target-branch: "main" + cooldown: + default-days: 7 - package-ecosystem: "maven" directory: "/" schedule: interval: "weekly" target-branch: "main" + cooldown: + default-days: 7 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7a054e6..6fbdb12 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,6 +19,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 6599573..c6c09c0 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -31,6 +31,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Set up JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -39,7 +41,7 @@ jobs: java-version: '21' - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 + uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -49,6 +51,6 @@ jobs: run: mvn --no-transfer-progress -B clean test-compile - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 + uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 7aab910..bca4dec 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -9,7 +9,9 @@ permissions: jobs: dependabot: runs-on: ubuntu-latest - if: github.actor == 'dependabot[bot]' + # Who opened the pull request, not who triggered this run: github.actor is whoever caused the event, + # and a run that Dependabot triggers on someone else's pull request would pass an actor check. + if: github.event.pull_request.user.login == 'dependabot[bot]' steps: - name: Fetch Dependabot metadata id: metadata diff --git a/.github/workflows/dependency-submission.yml b/.github/workflows/dependency-submission.yml index 4b4c6bc..73f2e85 100644 --- a/.github/workflows/dependency-submission.yml +++ b/.github/workflows/dependency-submission.yml @@ -12,6 +12,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Set up JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 3410113..4e213e6 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -31,6 +31,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -91,6 +92,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 diff --git a/.github/workflows/sha-pinning-check.yml b/.github/workflows/sha-pinning-check.yml index 16cfdd7..181c6e7 100644 --- a/.github/workflows/sha-pinning-check.yml +++ b/.github/workflows/sha-pinning-check.yml @@ -6,10 +6,15 @@ on: push: branches: [ 'main' ] +permissions: + contents: read + jobs: pin-check: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - uses: zgosalvez/github-actions-ensure-sha-pinned-actions@62574f011e0d1967d555a862bd28a7abba8684fe # v5.0.9 diff --git a/.github/workflows/update-pr-branch.yml b/.github/workflows/update-pr-branch.yml index d0ef7a7..eff6c9c 100644 --- a/.github/workflows/update-pr-branch.yml +++ b/.github/workflows/update-pr-branch.yml @@ -7,6 +7,10 @@ on: # Run every hour to catch stuck PRs - cron: '0 * * * *' +# The action reads and updates the pull requests with BOT_PAT alone, so the workflow's own token needs +# no permissions. +permissions: {} + jobs: update: runs-on: ubuntu-latest