Commit eb71c24
Conduction Release Bot
fix(ci): least-privilege workflow permissions + drop a dead string replace
Clears all 10 open CodeQL alerts on `development`: 9 workflow-hardening findings
and 1 dead no-op in production code. Neither category is a vulnerability that
was exploitable, and the check-run title ("7 new alerts including 3 high
severity security vulnerabilities") overstates both. All three "high severity"
alerts are `js/insecure-randomness` in Playwright fixtures; they are handled by
dismissal, not by this commit.
1. Nine `actions/missing-workflow-permissions`, all MEDIUM, all in
`.github/workflows/`. An absent `permissions:` block means the job runs with
the repository default rather than a stated grant.
Eight of the nine only CALL a reusable workflow in ConductionNL/.github, so
the block restates what the callee's own job already declares and the
effective token is unchanged:
release-beta / release-development / release-stable contents: write
sync-to-beta contents: write + pull-requests: write
issue-triage issues: write + contents: read
openspec-sync issues: write + contents: read
documentation contents: write + packages: write (UNION of the
callee's build / deploy / image jobs)
branch-protection {} — the callee is one bash string comparison with
no checkout, no network and no API call
code-quality is the exception and the only risky one. Most jobs in the shared
quality pipeline declare no permissions of their own, so they inherit the
caller ceiling exactly. The block used is copied verbatim from openconnector,
where it is live on `development` with ~30 quality jobs green — a measured
ceiling, not a guess.
A caller block is a CEILING, not a grant: GitHub validates the callee's
declared job permissions against it, including for jobs an `if:` will skip,
so tightening one to `read` makes the call fail to START with zero jobs.
2. One `js/identity-replacement` (MEDIUM) at src/views/Dashboard.vue:496 —
`.replace(',', ',')`, replacing the comma with itself.
It was born in that identical form in 5c33f0b ("Working on the detail
pages"), so it never worked and no intent is recorded to recover. Deleting it
is output-preserving: `formatDate` still returns `17/08/2026, 08:33`,
verified against the actual string. Guessing at `.replace(',', '')` would
have invented a UI change nothing asked for.
Checked and ruled out while here: `toLocaleDateString` with explicit
`hour`/`minute` options DOES emit the time (ECMA-402 supplies date-part
defaults only when none are given), so this was not the "the time is silently
missing" bug it resembles. Measured, not assumed.
Verified: all 11 workflows parse, and a job-level sweep reports 0 jobs without a
block, against 9 before the change — the same 9 CodeQL names.1 parent 68202d5 commit eb71c24
10 files changed
Lines changed: 133 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
11 | 17 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
83 | 83 | | |
84 | 84 | | |
85 | 85 | | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
86 | 116 | | |
87 | 117 | | |
88 | 118 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
11 | 25 | | |
12 | 26 | | |
13 | 27 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
15 | 24 | | |
16 | 25 | | |
17 | 26 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
11 | 19 | | |
12 | 20 | | |
13 | 21 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
10 | 23 | | |
11 | 24 | | |
12 | 25 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
32 | 43 | | |
33 | 44 | | |
34 | 45 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
10 | 20 | | |
11 | 21 | | |
12 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
10 | 21 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
480 | 480 | | |
481 | 481 | | |
482 | 482 | | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
483 | 497 | | |
484 | 498 | | |
485 | 499 | | |
486 | 500 | | |
487 | 501 | | |
488 | | - | |
489 | | - | |
490 | | - | |
491 | | - | |
492 | | - | |
493 | | - | |
494 | | - | |
495 | | - | |
496 | | - | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
497 | 509 | | |
498 | 510 | | |
499 | 511 | | |
| |||
0 commit comments