ci: split pr quality gates for mobile and desktop #268

Merged
talksik merged 1 commits from fix-pr-quality-gates into main 2026-06-11 17:57:04 +00:00
talksik commented 2026-06-11 17:49:19 +00:00 (Migrated from github.com)

Summary by CodeRabbit

  • Chores
    • Reorganized CI/CD quality gate workflows to independently verify desktop and mobile app changes for streamlined continuous integration processes.
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Reorganized CI/CD quality gate workflows to independently verify desktop and mobile app changes for streamlined continuous integration processes. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
coderabbitai[bot] commented 2026-06-11 17:50:22 +00:00 (Migrated from github.com)

Review Change Stack

📝 Walkthrough

Walkthrough

The PR separates the PR quality gate workflows by platform: the desktop workflow is narrowed to desktop-only changes, and a new mobile-specific workflow is created to enforce the same lint and format checks for mobile code independently.

Changes

Platform-specific CI workflows

Layer / File(s) Summary
Separate desktop and mobile quality gate workflows
.github/workflows/pr-quality-gate-desktop.yml, .github/workflows/pr-quality-gate-mobile.yml
Desktop workflow refactored to trigger only on js/desktop/** changes with a single verify job; new mobile workflow created to independently enforce yarn lint and yarn format:check on js/mobile/** changes, both using Node.js 20 with immutable dependency installation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Poem

🐰 Workflows split clean, like a path through the wood,
Desktop and mobile, each does its own good,
Quality gates stand guard on their respective ways,
Lint and format checks through all of our days!

🚥 Pre-merge checks | 5
Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title 'ci: split pr quality gates for mobile and desktop' accurately and concisely describes the main change in the changeset.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-pr-quality-gates

Comment @coderabbitai help to get the list of available commands and usage tips.

<!-- This is an auto-generated comment: summarize by coderabbit.ai --> <!-- review_stack_entry_start --> [![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/flowy-live/llink/pull/268?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- walkthrough_start --> <details> <summary>📝 Walkthrough</summary> ## Walkthrough The PR separates the PR quality gate workflows by platform: the desktop workflow is narrowed to desktop-only changes, and a new mobile-specific workflow is created to enforce the same lint and format checks for mobile code independently. ## Changes **Platform-specific CI workflows** |Layer / File(s)|Summary| |---|---| |**Separate desktop and mobile quality gate workflows** <br> `.github/workflows/pr-quality-gate-desktop.yml`, `.github/workflows/pr-quality-gate-mobile.yml`|Desktop workflow refactored to trigger only on `js/desktop/**` changes with a single `verify` job; new mobile workflow created to independently enforce `yarn lint` and `yarn format:check` on `js/mobile/**` changes, both using Node.js 20 with immutable dependency installation.| ## Estimated code review effort 🎯 2 (Simple) | ⏱️ ~8 minutes ## Poem > 🐰 Workflows split clean, like a path through the wood, > Desktop and mobile, each does its own good, > Quality gates stand guard on their respective ways, > Lint and format checks through all of our days! ✨ </details> <!-- walkthrough_end --> <!-- pre_merge_checks_walkthrough_start --> <details> <summary>🚥 Pre-merge checks | ✅ 5</summary> <details> <summary>✅ Passed checks (5 passed)</summary> | Check name | Status | Explanation | | :------------------------: | :------- | :--------------------------------------------------------------------------------------------------------------------------------- | | Description Check | ✅ Passed | Check skipped - CodeRabbit’s high-level summary is enabled. | | Title check | ✅ Passed | The title 'ci: split pr quality gates for mobile and desktop' accurately and concisely describes the main change in the changeset. | | Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. | | Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. | | Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. | </details> <sub>✏️ Tip: You can configure your own custom pre-merge checks in the settings.</sub> </details> <!-- pre_merge_checks_walkthrough_end --> <!-- finishing_touch_checkbox_start --> <details> <summary>✨ Finishing Touches</summary> <details> <summary>🧪 Generate unit tests (beta)</summary> - [ ] <!-- {"checkboxId": "f47ac10b-58cc-4372-a567-0e02b2c3d479", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} --> Create PR with unit tests - [ ] <!-- {"checkboxId": "6ba7b810-9dad-11d1-80b4-00c04fd430c8", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} --> Commit unit tests in branch `fix-pr-quality-gates` </details> </details> <!-- finishing_touch_checkbox_end --> <!-- tips_start --> --- <sub>Comment `@coderabbitai help` to get the list of available commands and usage tips.</sub> <!-- tips_end --> <!-- internal state start --> <!-- DwQgtGAEAqAWCWBnSTIEMB26CuAXA9mAOYCmGJATmriQCaQDG+Ats2bgFyQAOFk+AIwBWJBrngA3EsgEBPRvlqU0AgfFwA6NPEgQAfACgjoCEejqANiS4N4XRNwvqefAI7Y0T3PKLVpkADN8PmZBeCt0DHolRABrAm4DADlsZgFKLgAmADYADgMAVQAlABkuWFxcbkQOAHpaonVYbAENJmZagIt8AHdZMCcpWosnDFja7mwR2pz8gsQMyFxPWMR4WIMAZXxsCgYSSAEqDAZYLgD4AA8wXjB3T3V+3xpEA2g0ClJcQ+PTrmZtBgtstcNgavxuGQDEUSBJ4CQepRwQYSioSBZkQBhCgkPz0ahZAAMOTAhOyYAAjBToBSAOwcAAsAE4OBSmQAtIz6YzgKBkej4AI4AjEMjKGj0dpsDCcFz8YSicRSGTyJhKKiqdRaHTckxQOCoVCYYWEUjkKgShSsdhcKg9SCIVIAijyOQKdUqNSabS6MCGHmmAwaRq4ZoCWo9YKxLq9RATCh3DxeJ5+MAxeL4bgaWTMCwcAwAIiLBgAxCXIABBACSovNeIdTo+8kFjFgmFIr0K3Fo9dDBwA4uoABItStieD4DDIAAKRUg92TkGeB0jFGj3XtBEC+AYYP4GAszawfcg6YS6G43C4J9X696kAwaDYkXoAANJxpJiMAPo49zSTRuGoWBEFfB972WT4SG+V8hDjM9M1qAAqJCwIACloChM24eAMCISBYLjUI1CsZDUIASg0GBYAOIRBAdXAKGwMRdhXNBkFOds6AdfAlhoyBbxje0MHvJQLnIZA0AdXCiAiV8pAoeAAlkMC6IESA0NwxAaDQAUhQWICLQOV9iPCEgwMwN8EO4VTBEQciABoBIQCJYhIEgcLwviDmsyBRlwWpvEhU5RHGIIKABb5tI85BsCiSg+OoBQp3wJwe0tNSNCMIwy0rCwaAtCcpyWXiTyUBgLA+agiuQFsSEubhgktYIeBaJwGEgdh1HhTsoCSScSGynLywAWUwJSAMgAAxMzK0fQ8AC9KCMEpcP8Ti8LoLgAGpMlqMAAGYKSMABRbT4Ei7i1QOHE4QRTqAnC2URroeBUkLYsDAgMAjGDJoWgjKMhLjW4F0eYhU1Mqxs1zfMiwLUty2rWtxW4x1WCbfghQ2jsjArWglHxB97sHXAR3Uitx0nZBBI3B8n24lDABwCWdIAARSTR5IH7PwNJGsIrHIwBcAhQxLvkY+AiFIChaqwV8vwsX8SH/bSwNhdhkDQ99IXIWhXyc19EFkE5YCwjB4CW/WCJxTMxT18jtz4WdkEgr4ZIIgFcIsqI/Iu9RuK3HH/Di9UCLg2ooZIMjXyouAVyBumxLWyTpLwuSFKUlTIDUsXW1C2q8G8yAcUapyFlwWLuEgFD+qUDQ4MgTJCRQpyyBUKxkBQpgS7QBhYhblAp2WEZkCUHWlBOHqBKaAjZA+LAtOHixfQu5g8Hb8zB7DoiBfMpzLOLuLkFfOeKCwfywKCEZem4t0T/nx3Io4EK+5jobcorfLxRqkqi/KyrCrUyxp1BqTVuItUmAIdqnUZTdWkEYfq5AsoomTq2LitAdoHVpPtQkp1zqXUlIoG6sJ4T2hII9JqXAXq0DeswD6CMvp+gDHyH2LY0B4FNGKIyhDrQyltGge06NnSulVEQjUXptS+kMHqaihpJJYHYSKM0qMeHSllEoZYZlCFKEON0PuDYMYumLlxFU7plCam9DqJhBgADaABvAsxxSBVloAWDgjiuLfmyEyEgABWTIuR9jZFEAEAsDkCxAVDG4gsf1QwA1prGeMiYHjeAhjQNM0gMxZhzBYMJBZtIfFwKtcgbiKThP5MUkgpSyn5MbC6aJccBIJ16IATAIXaZgGOrZebBljpSkgfCWUskQCUoAcIO9AtxSWsmASch5ICs2XBpeWwFwTh2stHRyL4i6wTsmBBYVMsA9HYsXACTEWI4gmbxMEBwpJrDTsZDOylbLqUXriPSRdeAkJ2MgNe+V4BgBzuXbAVdQxJVwhVbAhN0Cnlegweskds6CA0Hk66AAhPRsRMQsEcPVR40S2A0NSAWAAvg5BxTiSAuOiRS78AQmRoDJISWkuRaQkGyL4vJkTYDRNiWGQGa5gZJLBqk5cYBI4w1yeEgpFAilrVKeUqIlS3FYKlXU2Q0SqwyiwrQZi/gpLkHtJiKsTSBV03CpABFztc5MWKrhbeEdd5W0Xp4DEMLx5kFsP4Ve68oGyH3j7Mg4V9jIH8u7A+4VIriC8i/VY+4TlWAkJgb4CsTkq2+OrGUiBkXhLRRirFzAcWXDxe4jcJKAC6zCYHvMUZwuslopQ2hhZoqw2iDhQJ3LEAxwjjGbVMddcRWofS6l5FaZg6hvzwFoIgJWd1ES0G/NK743IDAyMJL4/YTdchoC3YSBkB1fG0FpLQBkaA6UE23QwBghI4V5FpJkEghIDpMkyB1ZdMipTjsndO26pC6Dfn5FIldI7PnfjYFBb8Mbp2LsAwYOxBhICQALEgWc6KO10HzWo6c+BoquPOJ4BYDl4OIaQAAeQUopAmZA3GBHwyQQjCGCy0B3NpRSeEsUKTQM4mUlB5qbBBFUrgdjSVEYLNdIonp1AAHUsI0GnBQcwuArDUYCLR+jiHECwB2BYWgqG+6zmU6pkTNDaBFDigAER3Hx1jRBECYhon3ajjFsB0aM5O0zGAFNWDs6FRzTEXMMeM+5sz0gGCKW4OISc3mHN4YxP5xDow3K0CrIgR00grPUaLGpgslVtJRdiDCR0+VEDUZsURhDcGEOVcQzGpIDMMvBcQKF+A4WiqQDy2EsrlX8kgjBL55zamqsFnqo4TA1VJwZbyw6WIzXIT0CgFipQ4mLFtMgAgIgsBOlSGXkIzGqA25QLoNmzrDHQhKAy0cs+MkOtVYY8ESWuFPB5dq2wDLMQmstfG514TVWKs3dE/Z2Iz2BOIc82MgH12/sFNBMV68fmBtdeG5VR8EWMAZcaeIRTBwADkth7COGcLwecnNvBLj8Mgc1CKD7WSx+gS9uw/BzIPkwSeCw5lvcUukF2/FPZYCDlvE8Qdy5HZu4h07wOCwXfNnhCHg2cTM4uEQViBnYvw9u4pRo80nt1a4AWDHSmvvw9+4Nmr2vEMWYYCx927HlCkBl11qHvXYf9eO4hxHo2UcZf6oEOKBzyc7B9nagXbZNr0AuB3X+sJPAeBoKeZjEto34A46QKimxpuXndkxi38f8JMCT2D0Kwu/s4kQKlPARUMvSf9rHrP1m/d8BPAEH3KOflIDufhPszBf6IGqogZSRdc824OKGYvmntOF8G2L8788ruq8Q3djXj2AdA9e3H2vCMqvfcq0brrJuXs6+KYlyAyXUscXB7P7r1BHdLDhy7obDUkdjdRzrybcQZu31EOwhY4FfZjG4q35zNMoy24IcjsfEqAKaf4ABmgduJ2RCU+l20u5+8+D2FgWue+8WuEiWx+ABFYKW0giAai6+lWm+5Wt+u+4uJGhcLYmwTAkIbWweHYecDm5+DuMO1+zuIud+I2yO5ez+AOU2b+9A6QcK1y3+CWf+KWABIyOIwBPs5qoY4BUwy8kBAE4+XWk+OukuM+t+yBmuS+puBYOwuAJGAQNBtsdmJiuBCwKWhBX2RGZaWWOWuAs4oOGWmQtIAgN6TIDAtAFIDITKDIW6uQtAB0uQAQV6viuQmQB0AgPiR0AQhIAguQTIwRbICRaA0RzIaAvi9KIR2QPYWRuQ/i2QCMxKlaIGYGpAEGAO06AGw6EAJo34QE1yC6/GrRhSMGDiTh04n+dAFYuAMIs66GLAY6uAWKcUuAbihIZRQGDRNaTRvR7RNA/6Ps9RUAuEBU80SxJAM6SARU7RMqnREuikNAVK7ihIbIJAAgR6B0YA+wfhYAtI+6AgYA26R6aY2QAgaA5CAQuQAgFxDAJKlaGxPGng2xuxawk4Kxc2foQAA== --> <!-- internal state end -->
coderabbitai[bot] (Migrated from github.com) reviewed 2026-06-11 17:56:15 +00:00
coderabbitai[bot] (Migrated from github.com) left a comment

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/pr-quality-gate-mobile.yml:
- Around line 19-25: Replace mutable action tags actions/checkout@v4 and
actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false
on the checkout step to reduce supply-chain and token exposure risk; update the
checkout step (actions/checkout) to include persist-credentials: false and
replace both uses entries (actions/checkout and actions/setup-node) with their
specific commit SHAs (use the official SHAs for the versions currently
referenced) so the workflow references immutable commits.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c764ac6d-9a10-4f74-8aa6-42ef51a52823

📥 Commits

Reviewing files that changed from the base of the PR and between 95f2362947 and 05ce208a8a.

📒 Files selected for processing (2)
  • .github/workflows/pr-quality-gate-desktop.yml
  • .github/workflows/pr-quality-gate-mobile.yml
**Actionable comments posted: 1** <details> <summary>🤖 Prompt for all review comments with AI agents</summary> ``` Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. Inline comments: In @.github/workflows/pr-quality-gate-mobile.yml: - Around line 19-25: Replace mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false on the checkout step to reduce supply-chain and token exposure risk; update the checkout step (actions/checkout) to include persist-credentials: false and replace both uses entries (actions/checkout and actions/setup-node) with their specific commit SHAs (use the official SHAs for the versions currently referenced) so the workflow references immutable commits. ``` </details> <details> <summary>🪄 Autofix (Beta)</summary> Fix all unresolved CodeRabbit comments on this PR: - [ ] <!-- {"checkboxId": "4b0d0e0a-96d7-4f10-b296-3a18ea78f0b9"} --> Push a commit to this branch (recommended) - [ ] <!-- {"checkboxId": "ff5b1114-7d8c-49e6-8ac1-43f82af23a33"} --> Create a new PR with the fixes </details> --- <details> <summary>ℹ️ Review info</summary> <details> <summary>⚙️ Run configuration</summary> **Configuration used**: defaults **Review profile**: CHILL **Plan**: Pro Plus **Run ID**: `c764ac6d-9a10-4f74-8aa6-42ef51a52823` </details> <details> <summary>📥 Commits</summary> Reviewing files that changed from the base of the PR and between 95f2362947076cea50ee50ef615e654ef1e0d45c and 05ce208a8a0435d7d4af9dda8cc0ca6872e0392c. </details> <details> <summary>📒 Files selected for processing (2)</summary> * `.github/workflows/pr-quality-gate-desktop.yml` * `.github/workflows/pr-quality-gate-mobile.yml` </details> </details> <!-- This is an auto-generated comment by CodeRabbit for review status -->
@@ -0,0 +22,4 @@
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
coderabbitai[bot] (Migrated from github.com) commented 2026-06-11 17:56:15 +00:00

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"

# Show file with line numbers around the referenced area
nl -ba "$FILE" | sed -n '1,120p'

# Also scan for other uses of actions/checkout and actions/setup-node in the repo for consistency
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

Repository: flowy-live/llink

Length of output: 103


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"
if [ ! -f "$FILE" ]; then
  echo "Missing file: $FILE"
  exit 1
fi

nl -ba "$FILE" | sed -n '1,160p'

echo "---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

echo "---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows || true

Repository: flowy-live/llink

Length of output: 104


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"
nl -ba "$FILE" | sed -n '1,200p'

echo "---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

echo "---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows || true

Repository: flowy-live/llink

Length of output: 103


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"

echo "=== pr-quality-gate-mobile.yml (lines 1-200) ==="
if [ -f "$FILE" ]; then
  cat -n "$FILE" | sed -n '1,200p'
else
  echo "Missing $FILE"
  exit 1
fi

echo "=== other workflows using checkout/setup-node (pinned or tag refs) ==="
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

echo "=== persist-credentials occurrences ==="
rg -n "persist-credentials" .github/workflows || true

Repository: flowy-live/llink

Length of output: 1941


Pin actions to commit SHAs and disable persisted checkout credentials in CI

.github/workflows/pr-quality-gate-mobile.yml uses mutable tag refs (actions/checkout@v4 at line 20, actions/setup-node@v4 at line 23) and the checkout step does not set persist-credentials: false, increasing supply-chain and token exposure risk.

Suggested hardening diff
       - name: Check out repository code
-        uses: actions/checkout@v4
+        uses: actions/checkout@<FULL_COMMIT_SHA>
+        with:
+          persist-credentials: false

       - name: Set up Node.js
-        uses: actions/setup-node@v4
+        uses: actions/setup-node@<FULL_COMMIT_SHA>
         with:
           node-version: '20'
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 19-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/pr-quality-gate-mobile.yml around lines 19 - 25, Replace
mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned
commit SHAs and set persist-credentials: false on the checkout step to reduce
supply-chain and token exposure risk; update the checkout step
(actions/checkout) to include persist-credentials: false and replace both uses
entries (actions/checkout and actions/setup-node) with their specific commit
SHAs (use the official SHAs for the versions currently referenced) so the
workflow references immutable commits.

Source: Linters/SAST tools

_⚠️ Potential issue_ | _🟠 Major_ <details> <summary>🧩 Analysis chain</summary> 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" # Show file with line numbers around the referenced area nl -ba "$FILE" | sed -n '1,120p' # Also scan for other uses of actions/checkout and actions/setup-node in the repo for consistency rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 103 --- 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" if [ ! -f "$FILE" ]; then echo "Missing file: $FILE" exit 1 fi nl -ba "$FILE" | sed -n '1,160p' echo "---- other workflows using checkout/setup-node ----" rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true echo "---- check for persist-credentials usage ----" rg -n "persist-credentials" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 104 --- 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" nl -ba "$FILE" | sed -n '1,200p' echo "---- other workflows using checkout/setup-node ----" rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true echo "---- check for persist-credentials usage ----" rg -n "persist-credentials" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 103 --- 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" echo "=== pr-quality-gate-mobile.yml (lines 1-200) ===" if [ -f "$FILE" ]; then cat -n "$FILE" | sed -n '1,200p' else echo "Missing $FILE" exit 1 fi echo "=== other workflows using checkout/setup-node (pinned or tag refs) ===" rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true echo "=== persist-credentials occurrences ===" rg -n "persist-credentials" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 1941 --- </details> **Pin actions to commit SHAs and disable persisted checkout credentials in CI** `.github/workflows/pr-quality-gate-mobile.yml` uses mutable tag refs (`actions/checkout@v4` at line 20, `actions/setup-node@v4` at line 23) and the checkout step does not set `persist-credentials: false`, increasing supply-chain and token exposure risk. <details> <summary>Suggested hardening diff</summary> ```diff - name: Check out repository code - uses: actions/checkout@v4 + uses: actions/checkout@<FULL_COMMIT_SHA> + with: + persist-credentials: false - name: Set up Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@<FULL_COMMIT_SHA> with: node-version: '20' ``` </details> <details> <summary>🧰 Tools</summary> <details> <summary>🪛 zizmor (1.25.2)</summary> [warning] 19-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) --- [error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) --- [error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) </details> </details> <details> <summary>🤖 Prompt for AI Agents</summary> ``` Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/pr-quality-gate-mobile.yml around lines 19 - 25, Replace mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false on the checkout step to reduce supply-chain and token exposure risk; update the checkout step (actions/checkout) to include persist-credentials: false and replace both uses entries (actions/checkout and actions/setup-node) with their specific commit SHAs (use the official SHAs for the versions currently referenced) so the workflow references immutable commits. ``` </details> <!-- fingerprinting:phantom:poseidon:hawk --> <!-- cr-comment:v1:d1e53b8162f207c4b8c489fe --> _Source: Linters/SAST tools_ <!-- This is an auto-generated comment by CodeRabbit -->
Sign in to join this conversation.