INNER CODE UNIT · Go

TestCIGrantsNoAmbientWritePermission

minekube/gate · ci_write_token_isolation_test.go:99

func TestCIGrantsNoAmbientWritePermission(t *testing.T) {
	workflow, _ := readCIIsolationWorkflow(t)
	if len(workflow.Permissions) != 0 {
		t.Fatalf("workflow permissions are %v; ci.yml must have no ambient token grant", workflow.Permissions)
	}

	// pinned-tools runs the pinned-tool toolchain guard
	// (.github/scripts/check-pinned-go-tools.sh): checkout without persisted
	// credentials + contents: read only, like the other code-running jobs.
	for _, name := range []string{"lint", "test", "docker-smoke", "pinned-tools"} {
		job := ciIsolationJob(t, workflow, name)
		if got := job.Permissions; len(got) != 1 || got["contents"] != "read" {
			t.Errorf("%s permissions are %v; code-running jobs must have contents: read only", name, got)
		}
		for _, step := range job.Steps {
			if strings.HasPrefix(step.Uses, "actions/checkout@") &&
				fmt.Sprint(step.With["persist-credentials"]) != "false" {
				t.Errorf("%s checkout %q persists credentials; tagged code could recover the token",

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…