From a9990e3cda7d56880bab538ad58d29ce66c36ee6 Mon Sep 17 00:00:00 2001 From: Steven Silvester Date: Mon, 18 Nov 2024 10:04:01 -0600 Subject: [PATCH 1/2] PYTHON-4969 Add GitHub Actions scanner --- .github/workflows/zizmor.yml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 00000000..0fbdbd6d --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,32 @@ +name: GitHub Actions Security Analysis with zizmor + +on: + push: + branches: ["main"] + pull_request: + branches: ["**"] + +jobs: + zizmor: + name: zizmor latest via Cargo + runs-on: ubuntu-latest + permissions: + security-events: write + steps: + - name: Checkout repository + uses: actions/checkout@v4 + with: + persist-credentials: false + - name: Setup Rust + uses: actions-rust-lang/setup-rust-toolchain@v1 + - name: Get zizmor + run: cargo install zizmor + - name: Run zizmor + run: zizmor --format sarif . > results.sarif + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + - name: Upload SARIF file + uses: github/codeql-action/upload-sarif@v3 + with: + sarif_file: results.sarif + category: zizmor From 6aabf6511770dc20404f61093c7757c5dce8430b Mon Sep 17 00:00:00 2001 From: Steven Silvester Date: Mon, 18 Nov 2024 10:05:27 -0600 Subject: [PATCH 2/2] address findings --- .github/workflows/codeql.yml | 1 + .github/workflows/dist.yml | 1 + .github/workflows/linters.yml | 4 ++++ .github/workflows/test-python.yml | 3 +++ 4 files changed, 9 insertions(+) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 91b18fe7..43d5b0d9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -42,6 +42,7 @@ jobs: uses: actions/checkout@v4 with: ref: ${{ inputs.ref }} + persist-credentials: false - name: Set up Python uses: actions/setup-python@v4 with: diff --git a/.github/workflows/dist.yml b/.github/workflows/dist.yml index 4fe653bb..ded8932c 100644 --- a/.github/workflows/dist.yml +++ b/.github/workflows/dist.yml @@ -22,6 +22,7 @@ jobs: - uses: actions/checkout@v4 with: ref: ${{ inputs.ref }} + persist-credentials: false - name: Set up Python uses: actions/setup-python@v4 with: diff --git a/.github/workflows/linters.yml b/.github/workflows/linters.yml index 75ed8fe5..dcf46d45 100644 --- a/.github/workflows/linters.yml +++ b/.github/workflows/linters.yml @@ -13,6 +13,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 + with: + persist-credentials: false - uses: actions/setup-python@v5 with: python-version: '3.10' @@ -29,6 +31,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 + with: + persist-credentials: false - uses: actions/setup-python@v5 with: cache: 'pip' diff --git a/.github/workflows/test-python.yml b/.github/workflows/test-python.yml index 6641f2fb..16bfb2e1 100644 --- a/.github/workflows/test-python.yml +++ b/.github/workflows/test-python.yml @@ -23,6 +23,8 @@ jobs: steps: - name: Checkout django-mongodb uses: actions/checkout@v4 + with: + persist-credentials: false - name: install the django-mongodb backend run: | pip3 install --upgrade pip @@ -33,6 +35,7 @@ jobs: repository: 'mongodb-forks/django' ref: 'mongodb-5.0.x' path: 'django_repo' + persist-credentials: false - name: Install system packages for Django's Python test dependencies run: | sudo apt-get update