Skip to content

Commit 574ef0b

Browse files
committed
Fail the check when settings name a file outside the repository
The check can't read such a file, so it can't tell whether it sets a permission mode.
1 parent 55ac4d7 commit 574ef0b

1 file changed

Lines changed: 11 additions & 4 deletions

File tree

‎.github/scripts/check_workflow_hardening.py‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -153,14 +153,21 @@ def permission_mode_problem(step: dict, exempt: bool) -> str | None:
153153
if arg.startswith("--settings=")
154154
]
155155
for where, value in settings:
156-
if "defaultMode" in settings_text(value):
156+
text = settings_text(value)
157+
if text is None:
158+
return (
159+
f"{where} names a file outside the repository, which this check cannot read. "
160+
"Use inline settings or a file inside the repository"
161+
)
162+
if "defaultMode" in text:
157163
return f"remove 'defaultMode' from {where}: settings must not set a permission mode"
158164
return None
159165

160166

161-
def settings_text(value) -> str:
167+
def settings_text(value) -> str | None:
162168
"""The settings JSON a 'settings' value stands for: the value itself, or the contents of
163-
the file it names when it is a path inside the repository."""
169+
the file it names when it is a path inside the repository. None when it names a path
170+
outside the repository."""
164171
text = str(value or "").strip()
165172
if not text or text.startswith("{"):
166173
return text
@@ -170,7 +177,7 @@ def settings_text(value) -> str:
170177
resolved = path.resolve()
171178
resolved.relative_to(root)
172179
except (OSError, ValueError):
173-
return text
180+
return None
174181
if resolved.is_file():
175182
return resolved.read_text(encoding="utf-8", errors="replace")
176183
return text

0 commit comments

Comments
 (0)