INNER CODE UNIT · Go
TestCIGrantsNoAmbientWritePermission
minekube/gate · ci_write_token_isolation_test.go:99
func TestCIGrantsNoAmbientWritePermission(t *testing.T) {
workflow, _ := readCIIsolationWorkflow(t)
if len(workflow.Permissions) != 0 {
t.Fatalf("workflow permissions are %v; ci.yml must have no ambient token grant", workflow.Permissions)
}
// pinned-tools runs the pinned-tool toolchain guard
// (.github/scripts/check-pinned-go-tools.sh): checkout without persisted
// credentials + contents: read only, like the other code-running jobs.
for _, name := range []string{"lint", "test", "docker-smoke", "pinned-tools"} {
job := ciIsolationJob(t, workflow, name)
if got := job.Permissions; len(got) != 1 || got["contents"] != "read" {
t.Errorf("%s permissions are %v; code-running jobs must have contents: read only", name, got)
}
for _, step := range job.Steps {
if strings.HasPrefix(step.Uses, "actions/checkout@") &&
fmt.Sprint(step.With["persist-credentials"]) != "false" {
t.Errorf("%s checkout %q persists credentials; tagged code could recover the token",