ECC/scripts/ci
Jamkris 7f971b7e6f fix(ci): treat 'permissions: write-all' as a write-permission gate
`WRITE_PERMISSION_PATTERN` in `validate-workflow-security.js`
enumerates named GitHub Actions scopes (`contents: write`,
`issues: write`, etc.) to decide whether a workflow needs to:
  - disable `persist-credentials` on `actions/checkout`
  - pass `--ignore-scripts` to `npm ci`

The pattern misses the top-level shorthand `permissions:
write-all`, which is the strictly broader form — it grants every
named scope write access in a single line. As a result, a
workflow that opts into write-all currently slips both gates.

Reproduced on `main` before this commit:

  $ cat /tmp/bad.yml
  name: bad
  on: [push]
  permissions: write-all
  jobs:
    do:
      runs-on: ubuntu-latest
      steps:
        - uses: actions/checkout@v4
        - run: npm ci

  $ ECC_WORKFLOWS_DIR=/tmp node scripts/ci/validate-workflow-security.js
  Validated workflow security for 1 workflow files
  $ echo $?
  0

Expected: at least two violations (missing `persist-credentials:
false`, missing `--ignore-scripts`).
Actual: passes silently.

Fix: add a sibling pattern `WRITE_ALL_PATTERN` that matches
`^\s*permissions:\s*write-all\b` and OR it with
`WRITE_PERMISSION_PATTERN` at the single gate. Both top-level
and job-level `permissions:` blocks satisfy the `^\s*` prefix.

After this commit the reproduction above exits 1 with:

  ERROR: bad.yml:8 - workflows with write permissions must disable checkout credential persistence
  ERROR: bad.yml:9 - workflows with write permissions must install npm dependencies with --ignore-scripts

Three new regression tests in `tests/ci/validate-workflow-security.test.js`:
  - rejects write-all + credential-persisting checkout
  - rejects write-all + `npm ci` without `--ignore-scripts`
  - allows write-all when both gates are satisfied (no over-block)

Test count: 14 → 17 in this file; full `yarn test` still green.

A separate `refs/pull/N/merge` bypass under `pull_request_target`
exists in the same validator and is fixed in the next commit.
2026-05-17 21:19:29 -04:00
..
catalog.js feat: add command registry and coverage checks (#1906) 2026-05-14 22:02:36 -04:00
check-unicode-safety.js feat: add observability readiness gate 2026-05-11 18:33:14 -04:00
generate-command-registry.js feat: add command registry and coverage checks (#1906) 2026-05-14 22:02:36 -04:00
scan-supply-chain-iocs.js security: cover gh-token-monitor token persistence 2026-05-17 17:46:35 -04:00
supply-chain-advisory-sources.js Add supply-chain advisory source refresh 2026-05-15 23:09:54 -04:00
validate-agents.js docs: salvage focused stale PR contributions 2026-05-11 05:31:12 -04:00
validate-commands.js fix: harden claude plugin manifest surfaces 2026-04-08 16:27:30 -07:00
validate-hooks.js fix: bootstrap plugin-installed hook commands safely 2026-04-14 20:24:21 -07:00
validate-install-manifests.js fix(installer): harden locale docs install 2026-05-17 20:46:04 -04:00
validate-no-personal-paths.js fix: harden CI validators 2026-05-11 03:08:43 -04:00
validate-rules.js feat: deliver v1.8.0 harness reliability and parity updates 2026-03-04 14:48:06 -08:00
validate-skills.js fix(ci): flag SKILL.md frontmatter defects in validate-skills (#1669) 2026-05-11 01:14:38 -04:00
validate-workflow-security.js fix(ci): treat 'permissions: write-all' as a write-permission gate 2026-05-17 21:19:29 -04:00