ajfabbri commented on code in PR #8450:
URL: https://github.com/apache/hadoop/pull/8450#discussion_r3125723202


##########
.github/workflows/tmpl_build_and_test.yml:
##########
@@ -86,6 +90,19 @@ jobs:
     name: Build Image ${{ inputs.os }}-${{ inputs.branch }}
     runs-on: ubuntu-24.04
     needs: [ precondition ]
+    # Security: this does not leak write access for our image repository to
+    # forked repos.
+    #
+    # We have `packages: write` permissions for our GITHUB_TOKEN below. 
However:
+    #
+    # - For `pull_request`, GitHub downgrades GITHUB_TOKEN permissions to
+    #   read-only.
+    # - For `push` triggers on a fork, the GITHUB_TOKEN retains write
+    #   permissions, but the `push` is happening in the context of the fork, 
not
+    #   the upstream repo.
+    # - For `pull_request_target` (not used here), image repo permissions are
+    #   scoped to the repository they run on. This prevents forks from writing
+    #   to our Apache Hadoop image repo.

Review Comment:
   I could probably word this better.
   
   `pull_request_target` always uses the base repo's default branch. So an 
attacker cannot add an action which prints/leaks secrets. As you put it, we 
trust the code we've already merged.
   
   I don't think forks can push images to our image repo, since GITHUB_TOKEN is 
scoped to the repository it runs on, for ghcr.io.
   
   This article is good: 
   
https://github.blog/changelog/2025-11-07-actions-pull_request_target-and-environment-branch-protections-changes/
   
   Note we're following the suggestions in the [What Should You 
Do](https://github.blog/changelog/2025-11-07-actions-pull_request_target-and-environment-branch-protections-changes/#what-you-should-do
   ) section.
   My goal here was "proving" that we cannot leak a GITHUB_TOKEN with write 
access to the official image repo. 



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to