Skip to content

fix(docker-build-images)!: restrict build-secret GitHub App tokens - #914

Merged
neilime merged 1 commit into
mainfrom
fix/restrict-build-github-app-token
Sep 28, 2026
Merged

neilime merged 1 commit into
mainfrom
fix/restrict-build-github-app-token

Conversation

@neilime

@neilime neilime commented Sep 28, 2026

Copy link
Copy Markdown
Member

Build-secret GitHub App tokens currently inherit every permission and repository available to the app installation. This change limits them to contents: read, defaults access to the calling repository, and adds an explicit repository list for private dependencies. Empty or whitespace-only lists are rejected when an app is configured.

Breaking change and migration

  • Builds that access other repositories must set build-secret-github-app-repositories to their comma- or newline-separated names under build-secret-github-app-owner.
  • Builds requiring writes or permissions beyond repository contents must receive separately scoped credentials through build-secrets.
with:
  build-secret-github-app-repositories: |
    application
    shared-library

This PR contains only the Docker build-token restriction and its documentation. The unrelated CI lint and Helm fixture fixes are separate.

Validation: actionlint and zizmor pass on the changed workflow; Prettier passes on its documentation. Executed the workflow validation script with single and multiple repositories, whitespace normalization, empty-list rejection, and no-app builds. GitHub-hosted integration tests have not been run locally.

@github-actions

Copy link
Copy Markdown
Contributor

Super-linter summary

Language Validation result
BIOME_FORMAT Pass ✅
BIOME_LINT Pass ✅
CHECKOV Pass ✅
GITHUB_ACTIONS Pass ✅
GITHUB_ACTIONS_ZIZMOR Pass ✅
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
JSCPD Pass ✅
MARKDOWN Pass ✅
MARKDOWN_PRETTIER Pass ✅
NATURAL_LANGUAGE Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Fail ❌
YAML Pass ✅
YAML_PRETTIER Pass ✅

Super-linter detected linting errors

For more information, see the GitHub Actions workflow run

Powered by Super-linter

TRIVY

Report Summary

┌──────────────────────────────────────────────┬────────────┬─────────────────┬───────────────────┬─────────┐
│                    Target                    │    Type    │ Vulnerabilities │ Misconfigurations │ Secrets │
├──────────────────────────────────────────────┼────────────┼─────────────────┼───────────────────┼─────────┤
│ actions/helm/generate-docs/package-lock.json │    npm     │        1        │         -         │    -    │
├──────────────────────────────────────────────┼────────────┼─────────────────┼───────────────────┼─────────┤
│ actions/helm/release-chart/package-lock.json │    npm     │        0        │         -         │    -    │
├──────────────────────────────────────────────┼────────────┼─────────────────┼───────────────────┼─────────┤
│ tests/charts/package-lock.json               │    npm     │        0        │         -         │    -    │
├──────────────────────────────────────────────┼────────────┼─────────────────┼───────────────────┼─────────┤
│ Dockerfile                                   │ dockerfile │        -        │         0         │    -    │
├──────────────────────────────────────────────┼────────────┼─────────────────┼───────────────────┼─────────┤
│ tests/application/Dockerfile                 │ dockerfile │        -        │         0         │    -    │
└──────────────────────────────────────────────┴────────────┴─────────────────┴───────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.69/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


actions/helm/generate-docs/package-lock.json (npm)
==================================================
Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌───────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬────────────────────────────────────────────────────────────┐
│  Library  │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                           Title                            │
├───────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────────┤
│ smol-toml │ CVE-2026-85730 │ HIGH     │ fixed  │ 1.7.0             │ 1.7.1         │ smol-toml: smol-toml: Denial of Service via malformed TOML │
│           │                │          │        │                   │               │ documents                                                  │
│           │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-85730                 │
└───────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴────────────────────────────────────────────────────────────┘

@neilime
neilime marked this pull request as ready for review September 28, 2026 19:01
Limit generated build tokens to contents:read and an explicit repository list.
Default to the calling repository and reject empty lists to prevent tokens
from falling back to installation-wide access.

BREAKING CHANGE: Build-secret GitHub App tokens no longer inherit all
installation permissions or access all installation repositories. Builds
using private dependencies must list those repositories with
build-secret-github-app-repositories. Operations requiring other permissions
must receive separately scoped credentials through build-secrets.
@neilime
neilime force-pushed the fix/restrict-build-github-app-token branch from b4b131e to f567c91 Compare September 28, 2026 19:22
@github-actions

Copy link
Copy Markdown
Contributor

Super-linter summary

Language Validation result
BIOME_FORMAT Pass ✅
BIOME_LINT Pass ✅
CHECKOV Pass ✅
GITHUB_ACTIONS Pass ✅
GITHUB_ACTIONS_ZIZMOR Pass ✅
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
JSCPD Pass ✅
MARKDOWN Pass ✅
MARKDOWN_PRETTIER Pass ✅
NATURAL_LANGUAGE Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Pass ✅
YAML Pass ✅
YAML_PRETTIER Pass ✅

All files and directories linted successfully

For more information, see the GitHub Actions workflow run

Powered by Super-linter

@neilime
neilime merged commit ad60282 into main Sep 28, 2026
174 checks passed
@neilime
neilime deleted the fix/restrict-build-github-app-token branch September 28, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant