Skip to content

ci: refactor build_docs so that pandoc runs in isolated read-only job [citest_skip] - #898

Merged
richm merged 1 commit into
mainfrom
build_docs-security-fixes
Aug 13, 2026
Merged

ci: refactor build_docs so that pandoc runs in isolated read-only job [citest_skip]#898
richm merged 1 commit into
mainfrom
build_docs-security-fixes

Conversation

@richm

@richm richm commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

The pandoc conversion part of the workflow does not need write access, so refactor
that into a separate job.

Add permissions to woke because it does not need write permisssion.

The latest security guidance is to use the full commit hash, which is immutable,
instead of a tag or version, which can be mutable, for the reference to a version
of a github action. There are known attacks which inserted unauthorized code
in a version tag and moved the tag. This prevents this sort of attack, at the
cost of more maintenance burden, but dependabot will largely take care of this
for us. We already did this for the other workflows, this is specific for the
build_docs workflow.

@richm richm self-assigned this Aug 13, 2026
@coderabbitai

coderabbitai Bot commented Aug 13, 2026

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (1)
  • [citest_skip]

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 25ccb712-5710-424e-be9c-aee8b350e4eb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@richm
richm force-pushed the build_docs-security-fixes branch from 52dde06 to d4b02a1 Compare August 13, 2026 19:20
… [citest_skip]

The pandoc conversion part of the workflow does not need write access, so refactor
that into a separate job.

Add permissions to woke because it does not need write permisssion.

The latest security guidance is to use the full commit hash, which is immutable,
instead of a tag or version, which can be mutable, for the reference to a version
of a github action.  There are known attacks which inserted unauthorized code
in a version tag and moved the tag.  This prevents this sort of attack, at the
cost of more maintenance burden, but dependabot will largely take care of this
for us.  We already did this for the other workflows, this is specific for the
build_docs workflow.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
@richm
richm merged commit 0dd0870 into main Aug 13, 2026
14 checks passed
@richm
richm deleted the build_docs-security-fixes branch August 13, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant