Skip to content

Commit 0075954

Browse files
rohityancopybara-github
authored andcommitted
fix: resolve zizmor security findings in GitHub Actions workflows
Merge #6601 This PR resolves 58 security and workflow linting findings identified by zizmor across 13 GitHub Actions workflow files. PiperOrigin-RevId: 962236543
1 parent 7169c46 commit 0075954

13 files changed

Lines changed: 80 additions & 47 deletions

‎.github/workflows/analyze-releases-for-adk-docs-updates.yml‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -45,10 +45,12 @@ jobs:
4545

4646
steps:
4747
- name: Checkout repository
48-
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
48+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
49+
with:
50+
persist-credentials: false
4951

5052
- name: Set up Python
51-
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
53+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
5254
with:
5355
python-version: '3.11'
5456

‎.github/workflows/block-merge.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,9 @@ on:
1919
branches: [main]
2020
types: [opened, reopened, synchronize]
2121

22+
permissions:
23+
contents: read
24+
2225
jobs:
2326
block-merge:
2427
if: github.repository == 'google/adk-python'

‎.github/workflows/continuous-integration.yml‎

Lines changed: 14 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,9 @@ jobs:
4040
runs-on: ubuntu-latest
4141
steps:
4242
- name: Checkout Code
43-
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
43+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
44+
with:
45+
persist-credentials: false
4446

4547
- name: Install the latest version of uv
4648
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7
@@ -61,12 +63,13 @@ jobs:
6163
python-version: ['3.10', '3.11', '3.12', '3.13']
6264
steps:
6365
- name: Checkout code
64-
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
66+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
6567
with:
68+
persist-credentials: false
6669
fetch-depth: 0
6770

6871
- name: Set up Python
69-
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
72+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
7073
with:
7174
python-version: ${{ matrix.python-version }}
7275

@@ -132,10 +135,12 @@ jobs:
132135
timeout-minutes: 10
133136
steps:
134137
- name: Checkout code
135-
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
138+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
139+
with:
140+
persist-credentials: false
136141

137142
- name: Set up Python ${{ matrix.python-version }}
138-
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
143+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
139144
with:
140145
python-version: ${{ matrix.python-version }}
141146

@@ -174,10 +179,12 @@ jobs:
174179
timeout-minutes: 10
175180
steps:
176181
- name: Checkout code
177-
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
182+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
183+
with:
184+
persist-credentials: false
178185

179186
- name: Set up Python ${{ matrix.python-version }}
180-
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
187+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
181188
with:
182189
python-version: ${{ matrix.python-version }}
183190

‎.github/workflows/copybara-pr-handler.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ jobs:
4040

4141
steps:
4242
- name: Check for Copybara commits and close PRs
43-
uses: actions/github-script@v8
43+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
4444
with:
4545
github-token: ${{ secrets.ADK_TRIAGE_AGENT }}
4646
script: |

‎.github/workflows/discussion_answering.yml‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -34,16 +34,18 @@ jobs:
3434

3535
steps:
3636
- name: Checkout repository
37-
uses: actions/checkout@v6
37+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
38+
with:
39+
persist-credentials: false
3840

3941
- name: Set up Python
40-
uses: actions/setup-python@v6
42+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
4143
with:
4244
python-version: '3.11'
4345

4446
- name: Authenticate to Google Cloud
4547
id: auth
46-
uses: 'google-github-actions/auth@v3'
48+
uses: 'google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093' # v3
4749
with:
4850
credentials_json: '${{ secrets.ADK_GCP_SA_KEY }}'
4951

‎.github/workflows/issue-maintenance.yml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -58,10 +58,12 @@ jobs:
5858
timeout-minutes: 120
5959
steps:
6060
- name: Checkout repository
61-
uses: actions/checkout@v6
61+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
62+
with:
63+
persist-credentials: false
6264

6365
- name: Set up Python
64-
uses: actions/setup-python@v6
66+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
6567
with:
6668
python-version: '3.11'
6769

@@ -84,10 +86,12 @@ jobs:
8486
timeout-minutes: 60
8587
steps:
8688
- name: Checkout repository
87-
uses: actions/checkout@v6
89+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
90+
with:
91+
persist-credentials: false
8892

8993
- name: Set up Python
90-
uses: actions/setup-python@v6
94+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
9195
with:
9296
python-version: '3.11'
9397

‎.github/workflows/pr-triage.yml‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -52,10 +52,12 @@ jobs:
5252

5353
steps:
5454
- name: Checkout repository
55-
uses: actions/checkout@v6
55+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
56+
with:
57+
persist-credentials: false
5658

5759
- name: Set up Python
58-
uses: actions/setup-python@v6
60+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
5961
with:
6062
python-version: '3.11'
6163

‎.github/workflows/release-cherry-pick.yml‎

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ jobs:
5151
echo "candidate_branch=release/candidate" >> $GITHUB_OUTPUT
5252
fi
5353
54-
- uses: actions/checkout@v6
54+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
5555
with:
5656
ref: ${{ steps.config.outputs.candidate_branch }}
5757
token: ${{ secrets.RELEASE_PAT }}
@@ -73,16 +73,17 @@ jobs:
7373
fi
7474
7575
- name: Cherry-pick commit
76+
env:
77+
CANDIDATE_BRANCH: ${{ steps.config.outputs.candidate_branch }}
78+
INPUTS_COMMIT_SHA: ${{ inputs.commit_sha }}
7679
run: |
77-
CANDIDATE_BRANCH="${{ steps.config.outputs.candidate_branch }}"
7880
echo "Cherry-picking ${INPUTS_COMMIT_SHA} to $CANDIDATE_BRANCH"
7981
git cherry-pick ${INPUTS_COMMIT_SHA}
80-
env:
81-
INPUTS_COMMIT_SHA: ${{ inputs.commit_sha }}
8282
8383
- name: Push changes
84+
env:
85+
CANDIDATE_BRANCH: ${{ steps.config.outputs.candidate_branch }}
8486
run: |
85-
CANDIDATE_BRANCH="${{ steps.config.outputs.candidate_branch }}"
8687
git push origin "$CANDIDATE_BRANCH"
8788
echo "Successfully cherry-picked commit to $CANDIDATE_BRANCH"
8889
echo "If you want to regenerate the changelog PR, run the 'Release: Cut' workflow manually"

‎.github/workflows/release-cut.yml‎

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,7 @@ jobs:
6969
# Action: CUT NEW RELEASE
7070
- name: Checkout base ref (Cut)
7171
if: inputs.action == 'cut'
72-
uses: actions/checkout@v6
72+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
7373
with:
7474
ref: ${{ inputs.commit_sha || steps.config.outputs.base_ref }}
7575
token: ${{ secrets.RELEASE_PAT }}
@@ -86,24 +86,25 @@ jobs:
8686
8787
- name: Create and push candidate branch (Cut)
8888
if: inputs.action == 'cut'
89+
env:
90+
CANDIDATE_BRANCH: ${{ steps.config.outputs.candidate_branch }}
8991
run: |
90-
CANDIDATE_BRANCH="${{ steps.config.outputs.candidate_branch }}"
9192
git checkout -b "$CANDIDATE_BRANCH"
9293
git push origin "$CANDIDATE_BRANCH"
9394
echo "Created and pushed branch: $CANDIDATE_BRANCH"
9495
9596
# Action: REGENERATE EXISTING PR
9697
- name: Checkout existing candidate branch (Regenerate)
9798
if: inputs.action == 'regenerate'
98-
uses: actions/checkout@v6
99+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
99100
with:
100101
ref: ${{ steps.config.outputs.candidate_branch }}
101102
token: ${{ secrets.RELEASE_PAT }}
102103

103104
# Run Release Please
104105
- name: Run Release Please
105106
id: release_please
106-
uses: googleapis/release-please-action@v4
107+
uses: googleapis/release-please-action@5c625bfb5d1ff62eadeeb3772007f7f66fdcf071 # v4
107108
with:
108109
token: ${{ secrets.RELEASE_PAT }}
109110
config-file: ${{ steps.config.outputs.config_file }}
@@ -118,7 +119,7 @@ jobs:
118119
# so it also runs when release-please updates an existing PR (regenerate).
119120
- name: Set up Python
120121
if: steps.release_please.outputs.pr != ''
121-
uses: actions/setup-python@v6
122+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
122123
with:
123124
python-version: '3.11'
124125

‎.github/workflows/release-finalize.yml‎

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -47,8 +47,9 @@ jobs:
4747
- name: Determine Branch Configurations
4848
if: steps.check.outputs.is_release_pr == 'true'
4949
id: config
50+
env:
51+
CANDIDATE_BRANCH: ${{ github.event.pull_request.base.ref }}
5052
run: |
51-
CANDIDATE_BRANCH="${{ github.event.pull_request.base.ref }}"
5253
if [ "$CANDIDATE_BRANCH" = "release/v1-candidate" ]; then
5354
echo "base_branch=v1" >> $GITHUB_OUTPUT
5455
echo "config_file=.github/release-please-config-v1.json" >> $GITHUB_OUTPUT
@@ -59,7 +60,7 @@ jobs:
5960
echo "manifest_file=.github/.release-please-manifest.json" >> $GITHUB_OUTPUT
6061
fi
6162
62-
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
63+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
6364
if: steps.check.outputs.is_release_pr == 'true'
6465
with:
6566
ref: ${{ github.event.pull_request.base.ref }}
@@ -69,8 +70,10 @@ jobs:
6970
- name: Extract version from manifest
7071
if: steps.check.outputs.is_release_pr == 'true'
7172
id: version
73+
env:
74+
MANIFEST_FILE: ${{ steps.config.outputs.manifest_file }}
7275
run: |
73-
VERSION=$(jq -r '.["."]' "${{ steps.config.outputs.manifest_file }}")
76+
VERSION=$(jq -r '.["."]' "$MANIFEST_FILE")
7477
echo "version=$VERSION" >> $GITHUB_OUTPUT
7578
echo "Extracted version: $VERSION"
7679
@@ -85,10 +88,11 @@ jobs:
8588
8689
- name: Record last-release-sha for release-please
8790
if: steps.check.outputs.is_release_pr == 'true'
91+
env:
92+
BASE_BRANCH: ${{ steps.config.outputs.base_branch }}
93+
CONFIG_FILE: ${{ steps.config.outputs.config_file }}
94+
CANDIDATE_BRANCH: ${{ github.event.pull_request.base.ref }}
8895
run: |
89-
BASE_BRANCH="${{ steps.config.outputs.base_branch }}"
90-
CONFIG_FILE="${{ steps.config.outputs.config_file }}"
91-
CANDIDATE_BRANCH="${{ github.event.pull_request.base.ref }}"
9296
9397
git fetch origin "$BASE_BRANCH"
9498
CUT_SHA=$(git merge-base "origin/$BASE_BRANCH" HEAD)
@@ -103,13 +107,13 @@ jobs:
103107
104108
- name: Rename candidate to release/v{version}
105109
if: steps.check.outputs.is_release_pr == 'true'
110+
env:
111+
STEPS_VERSION_OUTPUTS_VERSION: ${{ steps.version.outputs.version }}
112+
CANDIDATE_BRANCH: ${{ github.event.pull_request.base.ref }}
106113
run: |
107114
VERSION="v${STEPS_VERSION_OUTPUTS_VERSION}"
108-
CANDIDATE_BRANCH="${{ github.event.pull_request.base.ref }}"
109115
git push origin "$CANDIDATE_BRANCH:refs/heads/release/$VERSION" ":$CANDIDATE_BRANCH"
110116
echo "Renamed $CANDIDATE_BRANCH to release/$VERSION"
111-
env:
112-
STEPS_VERSION_OUTPUTS_VERSION: ${{ steps.version.outputs.version }}
113117
114118
- name: Update PR label to tagged
115119
if: steps.check.outputs.is_release_pr == 'true'

0 commit comments

Comments
 (0)