fix(docker-build-images)!: restrict build-secret GitHub App tokens - #914
Merged
Merged
Conversation
Contributor
Super-linter summary
Super-linter detected linting errors For more information, see the GitHub Actions workflow run Powered by Super-linter TRIVY |
neilime
marked this pull request as ready for review
September 28, 2026 19:01
Limit generated build tokens to contents:read and an explicit repository list. Default to the calling repository and reject empty lists to prevent tokens from falling back to installation-wide access. BREAKING CHANGE: Build-secret GitHub App tokens no longer inherit all installation permissions or access all installation repositories. Builds using private dependencies must list those repositories with build-secret-github-app-repositories. Operations requiring other permissions must receive separately scoped credentials through build-secrets.
neilime
force-pushed
the
fix/restrict-build-github-app-token
branch
from
September 28, 2026 19:22
b4b131e to
f567c91
Compare
Contributor
Super-linter summary
All files and directories linted successfully For more information, see the GitHub Actions workflow run Powered by Super-linter |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Build-secret GitHub App tokens currently inherit every permission and repository available to the app installation. This change limits them to
contents: read, defaults access to the calling repository, and adds an explicit repository list for private dependencies. Empty or whitespace-only lists are rejected when an app is configured.Breaking change and migration
build-secret-github-app-repositoriesto their comma- or newline-separated names underbuild-secret-github-app-owner.build-secrets.This PR contains only the Docker build-token restriction and its documentation. The unrelated CI lint and Helm fixture fixes are separate.
Validation: actionlint and zizmor pass on the changed workflow; Prettier passes on its documentation. Executed the workflow validation script with single and multiple repositories, whitespace normalization, empty-list rejection, and no-app builds. GitHub-hosted integration tests have not been run locally.