Skip to content

[Aikido] Restrict OIDC id-token write permission to build job in publish workflow - #739

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137917403-qxdf
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137917403-qxdf

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch mitigates an OIDC token privilege escalation vulnerability in the publish workflow by removing the overly permissive id-token: write permission from the workflow-level scope. The id-token write permission has been restricted to only the build job that requires it for PyPI publishing, preventing the tests job from being able to mint publishing tokens. The fix was applied to .github/workflows/publish.yml by moving the permission scope from the workflow level to the specific job that needs it.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811708017
HIGH
The workflow-wide id-token: write permission is inherited by both tests and build. The tests job checks out repository-controlled code, installs dependencies, runs an unpinned remote installer, and executes tests. Code compromised in any of those paths can request an OIDC token from GitHub and present it to the PyPI trusted-publisher endpoint used by the workflow's PyPI publishing action. PyPI trusted-publisher identity is based on workflow-level claims rather than the intended job boundary, so the pre-publish job can obtain the same release authority without repository write access. Restrict id-token: write to build.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant