Andrea Cosentino created CAMEL-24502:
----------------------------------------
Summary: Build and CI hardening - workflow token scope, job
separation and Maven wrapper checksums
Key: CAMEL-24502
URL: https://issues.apache.org/jira/browse/CAMEL-24502
Project: Camel
Issue Type: Improvement
Components: build system
Reporter: Andrea Cosentino
Assignee: Andrea Cosentino
Three build-infrastructure items, none affecting shipped artifacts.
*1. No permissions block on the sync workflows*
{{.github/workflows/automatic-sync-main.yml}} and {{generate-sbom-main.yml}}
declare no {{permissions:}} block, so their jobs run with the repository
default {{GITHUB_TOKEN}} grants rather than the minimum they need ({{contents:
write}}, {{pull-requests: write}}).
*2. Build of another repository shares a job with the PR-creation step*
{code:yaml}
- name: Checkout Camel project
uses: actions/checkout@v7
with:
repository: apache/camel
...
- name: Build Camel Project
run: ./mvnw -V --no-transfer-progress -Dquickly clean install
working-directory: ${{ github.workspace }}/camel
...
- name: Create Pull Request
uses: peter-evans/[email protected]
with:
token: ${{ secrets.GITHUB_TOKEN }}
{code}
The job builds {{apache/camel}} - running that repository's wrapper and build
plugins - and then uses the token in the same job. {{persist-credentials:
false}} is already set on both checkouts, which helps, but the grants still
apply for the whole job.
Splitting into a build job with {{contents: read}} that uploads the regenerated
tree as an artifact, and a separate job holding the write grants, would keep
the two apart. {{uses:}} references pinned to a full commit SHA rather than a
tag would let the existing github-actions dependabot ecosystem bump them.
*3. Maven wrapper downloads are unpinned*
{code:properties}
wrapperVersion=3.3.4
distributionType=bin
distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.11/apache-maven-3.9.11-bin.zip
wrapperUrl=https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.3.4/maven-wrapper-3.3.4.jar
{code}
No {{distributionSha256Sum}} or {{wrapperSha256Sum}}. {{mvnw}} enforces the
latter when present. A {{maven-wrapper.jar}} is also checked in, which the
wrapper's script-only mode would remove in favour of a checksum-verified
download.
*Proposal*: add the least-privilege {{permissions:}} blocks, split the sync
jobs, add both checksums, and consider script-only wrapper mode.
----
_This issue was drafted by Claude Code on behalf of Andrea Cosentino._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)