Skip to content

Harden the release workflows against injected values - #139

Merged
erseco merged 1 commit into
hotfix/admin-preview-opaque-originfrom
feature/ci-harden-workflows
Sep 26, 2026
Merged

erseco merged 1 commit into
hotfix/admin-preview-opaque-originfrom
feature/ci-harden-workflows

Conversation

@erseco

@erseco erseco commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Stacked on #138.

Workflow hardening

Two workflows expanded external values straight into shell scripts, inside jobs that hold a write token.

  • check-editor-releases.yml
    • Problem: the upstream exelearning/exelearning release tag_name was expanded directly into run: steps. This job holds contents: write and actions: write.
    • Fix: the tag must match ^v[0-9][0-9A-Za-z.-]*$, and later steps read it through env:.
  • release.yml
    • Problem: the workflow_dispatch inputs were expanded into the script and written to GITHUB_ENV unchecked. A newline in any of them would define arbitrary variables, such as BASH_ENV, for every later step.
    • Fix: the inputs are read through env: and validated first.
  • Both workflows: they build the editor from third-party packages, so actions/checkout now uses persist-credentials: false. check-editor-releases passes the token only to its single git push.
  • npm: applied the non-breaking npm audit fix to the dev tree (21 → 17 advisories). The rest need major @wp-playground/wp-env bumps and are left to Dependabot.

Not changed on purpose

  • Pinning third-party actions to SHAs: left out. AGENTS.md records a preference for version tags maintained by Renovate.
  • composer.lock: it is gitignored, so CI already resolves the patched PHPCS, WPCS and PHPCSUtils releases.

Verification

actionlint reports no errors. The only notices are the same 19 shellcheck info/style notices that were already reported before this change.

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Test in WordPress Playground

Test the plugin with the code from this branch:

Preview in WordPress Playground

ℹ️ The eXeLearning editor is fetched from the shared release and unpacked into the plugin when the playground boots, so the first load may take a few extra seconds. ELP upload, shortcode, Gutenberg block and preview work normally.

@codecov-commenter

codecov-commenter commented Sep 26, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.87%. Comparing base (9f8fb53) to head (952aac1).

Additional details and impacted files
@@                          Coverage Diff                          @@
##             hotfix/admin-preview-opaque-origin     #139   +/-   ##
=====================================================================
  Coverage                                 96.87%   96.87%           
  Complexity                                  864      864           
=====================================================================
  Files                                        39       39           
  Lines                                      4324     4324           
=====================================================================
  Hits                                       4189     4189           
  Misses                                      135      135           
Flag Coverage Δ
javascript 95.71% <ø> (ø)
php 97.25% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@erseco
erseco added this pull request to stack #144 September 26, 2026 07:38
@erseco
erseco force-pushed the feature/ci-harden-workflows branch from d5649e7 to 2cfb366 Compare September 26, 2026 07:43
@erseco
erseco force-pushed the feature/ci-harden-workflows branch from 2cfb366 to 952aac1 Compare September 26, 2026 08:01
check-editor-releases expanded the upstream release tag straight into shell
steps of a job holding contents: write. The tag is now validated as a plain
version tag and passed to later steps through env.

release expanded workflow_dispatch inputs into the script and wrote them to
GITHUB_ENV unchecked, where a newline would define arbitrary variables for
every later step. Inputs are read through env and validated first.

Both workflows build the editor from third-party packages, so actions/checkout
no longer leaves the write token in .git/config; check-editor-releases hands
it to its single push explicitly.

Also apply the non-breaking npm audit fixes to the dev dependency tree.
@erseco
erseco force-pushed the feature/ci-harden-workflows branch from 952aac1 to 9bd0209 Compare September 26, 2026 08:29
@erseco
erseco merged commit 5c9283a into main Sep 26, 2026
5 checks passed
@erseco
erseco deleted the feature/ci-harden-workflows branch September 26, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants