chore: use labels fork ignoring archived labels - #1774
Conversation
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThe GitHub Actions label-sync job now runs the forked labels implementation from the File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path=".github/workflows/labels.yml" line_range="20" />
<code_context>
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
- name: Sync config with Github
- run: uvx labels -u ${{ github.repository_owner }} -t ${{ secrets.GITHUB_TOKEN }} sync -f .github/labels.toml
+ run: uvx --with https://github.com/browniebroke/labels/archive/fix/ignore-archived-at.zip labels -u ${{ github.repository_owner }} -t ${{ secrets.GITHUB_TOKEN }} sync -f .github/labels.toml
</code_context>
<issue_to_address>
**🚨 issue (security):** The workflow executes code fetched from the mutable `fix/ignore-archived-at` branch and gives that code a token with `issues: write`; a branch rewrite or repository compromise can therefore exfiltrate the token or modify repository labels.
**Triggers:** When the fork branch is force-pushed, compromised, or otherwise modified.
**Suggested fix:** Pin the dependency to an immutable commit or verified release artifact instead of a branch archive URL.
</issue_to_address>Sourcery assessment
Needs a human reviewer. 1 finding to address first, and the workflow now downloads and executes an unpinned archive from a GitHub branch while supplying a repository token, so a faulty or changed dependency could make unintended API calls or modify repository metadata. Reverting stops future runs, but any labels or other repository changes made before the revert may require separate repair.
Blocking findings: .github/workflows/labels.yml:20
| - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 | ||
| - name: Sync config with Github | ||
| run: uvx labels -u ${{ github.repository_owner }} -t ${{ secrets.GITHUB_TOKEN }} sync -f .github/labels.toml | ||
| run: uvx --with https://github.com/browniebroke/labels/archive/fix/ignore-archived-at.zip labels -u ${{ github.repository_owner }} -t ${{ secrets.GITHUB_TOKEN }} sync -f .github/labels.toml |
There was a problem hiding this comment.
🚨 issue (security): The workflow executes code fetched from the mutable fix/ignore-archived-at branch and gives that code a token with issues: write; a branch rewrite or repository compromise can therefore exfiltrate the token or modify repository labels.
Triggers: When the fork branch is force-pushed, compromised, or otherwise modified.
Suggested fix: Pin the dependency to an immutable commit or verified release artifact instead of a branch archive URL.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1774 +/- ##
=======================================
Coverage 99.92% 99.92%
=======================================
Files 37 37
Lines 1333 1333
Branches 71 71
=======================================
Hits 1332 1332
Partials 1 1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Committed via https://github.com/asottile/all-repos
Summary by Sourcery
Enhancements: