diff --git a/.github/dependabot.yml b/.github/dependabot.yml index bcbfe28b0..1e2948d10 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,13 +1,19 @@ version: 2 +# A release is proposed only once it is a week old: a compromised or broken release is usually pulled +# within days. The cooldown holds back version updates only; security updates still come at once. updates: - package-ecosystem: "github-actions" directory: "/" schedule: interval: "weekly" target-branch: "main" + cooldown: + default-days: 7 - package-ecosystem: "gradle" directory: "/" schedule: interval: "weekly" target-branch: "main" + cooldown: + default-days: 7 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index cbdedd806..9b2cfdd72 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,6 +19,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -63,6 +65,8 @@ jobs: out until the wrapper's Gradle supports Java 27. steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Install JDK ${{ matrix.jdk }} for the tests id: test-jdk @@ -85,11 +89,14 @@ jobs: REASON: ${{ matrix.gradle_args_reason }} run: echo "::notice title=JDK ${{ matrix.jdk }} runs with $GRADLE_ARGS::$REASON" - # Gradle does not look into the runner's tool cache, so it is told where the test JDK is. + # Gradle does not look into the runner's tool cache, so it is told where the test JDK is. The path is + # a step's output, so it reaches the shell as a variable rather than being pasted into the script. - name: Build + env: + TEST_JDK: ${{ steps.test-jdk.outputs.path }} run: >- ./gradlew test -PjavaRuntime=${{ matrix.jdk }} ${{ matrix.gradle_args }} - -Porg.gradle.java.installations.paths=${{ steps.test-jdk.outputs.path }} + -Porg.gradle.java.installations.paths="$TEST_JDK" - name: Publish Test Report uses: mikepenz/action-junit-report@a9170d5795813c01ab4901ffb045b52bab4ab09d # v6.5.0 @@ -126,6 +133,8 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false # The jars compile with a Java 21 toolchain, which gradle.properties looks up in JDK21_HOME. On # Linux and macOS Gradle also finds the runner's own JDK 21 by its location, on Windows it does not. diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index d875a721d..e4807befe 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -27,6 +27,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Set up JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -35,7 +37,7 @@ jobs: java-version: '21' - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 + uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -46,6 +48,6 @@ jobs: run: ./gradlew --no-build-cache clean compileJava compileTestJava - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 + uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 7aab91003..bca4dec03 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -9,7 +9,9 @@ permissions: jobs: dependabot: runs-on: ubuntu-latest - if: github.actor == 'dependabot[bot]' + # Who opened the pull request, not who triggered this run: github.actor is whoever caused the event, + # and a run that Dependabot triggers on someone else's pull request would pass an actor check. + if: github.event.pull_request.user.login == 'dependabot[bot]' steps: - name: Fetch Dependabot metadata id: metadata diff --git a/.github/workflows/dependency-submission.yml b/.github/workflows/dependency-submission.yml index f25a4ff13..e4c029c9c 100644 --- a/.github/workflows/dependency-submission.yml +++ b/.github/workflows/dependency-submission.yml @@ -12,6 +12,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Set up a bootstrap JDK uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index dbe21dafa..f53532512 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -39,6 +39,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -100,6 +101,8 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false # The Java 21 toolchain for the jars, through JDK21_HOME, as in ci.yml: Gradle does not find the # runner's own JDK 21 on Windows. Installed before GraalVM, so that Gradle still runs on GraalVM. @@ -143,6 +146,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -207,6 +211,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -244,6 +249,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -286,6 +292,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 @@ -325,6 +332,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Install JDK 21 uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 diff --git a/.github/workflows/sha-pinning-check.yml b/.github/workflows/sha-pinning-check.yml index 16cfdd7fb..181c6e7bb 100644 --- a/.github/workflows/sha-pinning-check.yml +++ b/.github/workflows/sha-pinning-check.yml @@ -6,10 +6,15 @@ on: push: branches: [ 'main' ] +permissions: + contents: read + jobs: pin-check: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - uses: zgosalvez/github-actions-ensure-sha-pinned-actions@62574f011e0d1967d555a862bd28a7abba8684fe # v5.0.9 diff --git a/.github/workflows/update-pr-branch.yml b/.github/workflows/update-pr-branch.yml index d0ef7a737..eff6c9c5b 100644 --- a/.github/workflows/update-pr-branch.yml +++ b/.github/workflows/update-pr-branch.yml @@ -7,6 +7,10 @@ on: # Run every hour to catch stuck PRs - cron: '0 * * * *' +# The action reads and updates the pull requests with BOT_PAT alone, so the workflow's own token needs +# no permissions. +permissions: {} + jobs: update: runs-on: ubuntu-latest