Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -235,6 +235,8 @@ permissions:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
Comment on lines 235 to +239

@gitar-bot gitar-bot Bot Sep 1, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Quality: New persist-credentials pattern not propagated or explained

The migration templates in .cursor/cirrus-github-migration.md (lines 313-320 and 1789-1795) grant contents: write and check out with the default persist-credentials: true, so every workflow generated from them reproduces exactly the token-persistence exposure this PR sets out to close; nothing in the diff updates them or states they are intentionally excluded. Additionally, the README change is snippet-only: the per-action "Required GitHub Permissions" sections that call out contents: write never mention persist-credentials: false, so a reader who copies only the permissions block (or is told to add contents: write, as at README:88-92) gets the elevated token without the mitigation. Add the with: persist-credentials: false to the migration templates and one sentence of rationale next to the contents: write requirement.

Apply the same pattern to both build-job templates in .cursor/cirrus-github-migration.md and document the rationale once in the README requirements prose.:

- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
  with:
    # contents: write is elevated for this job; don't leave that token in
    # .git/config where PR-authored build code could reuse it.
    persist-credentials: false

Was this helpful? React with 👍 / 👎

- uses: SonarSource/ci-github-actions/config-maven@v1
- run: mvn verify
```
Expand Down Expand Up @@ -337,6 +339,8 @@ permissions:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
Comment on lines 341 to +343

@gitar-bot gitar-bot Bot Sep 1, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Bug: persist-credentials: false breaks git fetch inside build-* actions

The build-maven, build-gradle, build-npm, build-poetry and build-yarn composite actions run git fetch --unshallow / git fetch origin "$GITHUB_BASE_REF" against origin to give SonarQube full history — these use the credential that actions/checkout writes into .git/config, not github.token from step env (no http.extraheader/GH_TOKEN is configured for git anywhere in the repo). With persist-credentials: false in a private repo the fetch is unauthenticated: build-gradle runs git fetch origin "$GITHUB_BASE_REF" unguarded on every PR (build-gradle/build.sh:74-77) and will fail the job, while the maven/npm/poetry/yarn variants swallow the failure with || true on the shallow path, so history is silently not unshallowed and new-code/blame analysis degrades with a green build — which is why the end-to-end test looked clean. Either keep credentials on the checkout for the build-* examples, or make the build actions authenticate git themselves (e.g. git -c http.extraheader="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GITHUB_TOKEN" | base64)" fetch ...) before documenting this pattern for them.

Revert persist-credentials: false in the six build- examples (build-maven, build-poetry, build-gradle, build-npm, build-yarn) until the actions authenticate their own git fetch; keep it only in the config- examples, which perform no git remote operations.:**

steps:
  - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
    with:
      # Full history for SonarQube; credentials stay persisted because the
      # build-* actions fetch from origin themselves.
      fetch-depth: 0
  - uses: SonarSource/ci-github-actions/build-gradle@v1

Was this helpful? React with 👍 / 👎

- uses: SonarSource/ci-github-actions/config-maven@v1
- uses: SonarSource/ci-github-actions/build-maven@v1
```
Expand Down Expand Up @@ -446,6 +450,8 @@ permissions:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/config-poetry@v1
- run: poetry install
```
Expand Down Expand Up @@ -532,6 +538,8 @@ jobs:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/build-poetry@v1
```

Expand Down Expand Up @@ -641,6 +649,8 @@ permissions:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/config-gradle@v1
- run: ./gradlew build
```
Expand Down Expand Up @@ -766,6 +776,8 @@ jobs:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/build-gradle@v1
```

Expand Down Expand Up @@ -969,6 +981,8 @@ config:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/config-npm@v1
```

Expand Down Expand Up @@ -1058,6 +1072,8 @@ jobs:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/build-npm@v1
```

Expand Down Expand Up @@ -1168,6 +1184,8 @@ jobs:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/build-yarn@v1
```

Expand Down Expand Up @@ -1236,6 +1254,8 @@ permissions:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: SonarSource/ci-github-actions/config-pip@v1
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
Expand Down Expand Up @@ -1350,6 +1370,8 @@ permissions:
contents: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false
- uses: jdx/mise-action@1648a7812b9aeae629881980618f079932869151 # v4.0.1
- uses: SonarSource/ci-github-actions/config-uv@v1
- run: jf uv sync
Expand Down
Loading