3376fa8017
ci: bump the github-actions group with 2 updates ( #1374 )
...
Bumps the github-actions group with 2 updates:
- Updates `actions/configure-pages` from 5 to 6
- Updates `actions/deploy-pages` from 4 to 5
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 18:17:37 -07:00
J Logan and GitHub
8653507f80
GH actions: do not interpolate template variables in run blocks. ( #1284 )
...
- Prevents injection of code during CI build.
2026-03-03 14:13:32 -08:00
Melissa Kilby and GitHub
ae279105a2
chore: restrict GitHub workflow permissions - future-proof ( #781 )
...
See https://github.com/swiftlang/github-workflows/issues/167 for
additional context
This approach aligns with security best practices, as detailed in the
following documentation:
-
https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
-
https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#defining-access-for-the-github_token-scopes
-
https://openssf.org/blog/2024/08/12/mitigating-attack-vectors-in-github-workflows/
The default GITHUB_TOKEN permissions are defined at the repository
level. This PR modifies the workflow-level overrides to conform to
OpenSSF best practices -> defense in depth.
Allow me to quote OpenSSF:
https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
> The highest score is awarded when the permissions definitions in each
workflow's yaml file are set as read-only at the top level and the
required write permissions are declared at the run-level.”
> Remediation steps
> - Set top-level permissions as read-all or contents: read as described
in GitHub's documentation.
> - Set any required write permissions at the job-level. Only set the
permissions required for that job; do not set permissions: write-all at
the job level.
Compare to the LLVM project:
Top-level: contents read, e.g.
https://github.com/swiftlang/llvm-project/blob/next/.github/workflows/build-ci-container-windows.yml#L3-L4
-> this makes it future-proof
Job-level: Allow write permissions as needed, e.g.
https://github.com/swiftlang/llvm-project/blob/next/.github/workflows/build-ci-container-windows.yml#L53-L58
Signed-off-by: Melissa Kilby <mkilby@apple.com >
2025-10-17 15:03:41 -07:00
Patrick Stöckle and GitHub
2327e899cf
Remove trailing whitespace from GitHub workflows ( #154 )
...
Remove trailing whitespace from GitHub workflows
2025-06-11 16:56:39 -07:00
Kathryn Baldauf and GitHub
eeddf6f7e7
Publish docs from main ( #67 )
...
We eventually only want to support building docs from release branches
and tags, however, while we're working to initially set up the docs, we
may have some churn. So we want to be able to publish from main during
that churn.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com >
2025-06-09 16:33:05 -07:00
Kathryn Baldauf and GitHub
d4e01c6579
Only allow publishing docs on release branch or tags ( #30 )
...
This removes the ability to deploy docs on the main branch and instead
only allows docs deployment on either a tag or a release branch. Docs
are also built (but not deployed) in the common job run by the build and
release pipelines.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com >
2025-06-06 21:49:49 -07:00
Kathryn Baldauf
7e0567cece
Fix typo in release branch name ( #14 )
...
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com >
2025-06-05 15:53:35 -07:00
Kathryn Baldauf
7ce2585531
Add token to allow deploying github pages ( #13 )
...
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com >
2025-06-05 15:53:24 -07:00
Kathryn Baldauf
ec4185fcc7
Publish docs github action ( #9 )
...
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com >
2025-06-05 15:53:13 -07:00