Repository navigation
[Aikido] Restrict OIDC id-token write permission to build job in publish workflow - #739
Closed
aikido-autofix[bot] wants to merge 1 commit into
Closed
aikido-autofix[bot] wants to merge 1 commit into
aikido-autofix[bot] wants to merge 1 commit into
Conversation
…n publish workflow
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This patch mitigates an OIDC token privilege escalation vulnerability in the publish workflow by removing the overly permissive
id-token: writepermission from the workflow-level scope. The id-token write permission has been restricted to only the build job that requires it for PyPI publishing, preventing the tests job from being able to mint publishing tokens. The fix was applied to.github/workflows/publish.ymlby moving the permission scope from the workflow level to the specific job that needs it.✅ 1 issue fixed by this PR
id-token: writepermission is inherited by bothtestsandbuild. The tests job checks out repository-controlled code, installs dependencies, runs an unpinned remote installer, and executes tests. Code compromised in any of those paths can request an OIDC token from GitHub and present it to the PyPI trusted-publisher endpoint used by the workflow's PyPI publishing action. PyPI trusted-publisher identity is based on workflow-level claims rather than the intended job boundary, so the pre-publish job can obtain the same release authority without repository write access. Restrictid-token: writetobuild.