ci: split pr quality gates for mobile and desktop #268

Merged
talksik merged 1 commits from fix-pr-quality-gates into main 2026-06-11 17:57:04 +00:00
talksik commented 2026-06-11 17:49:19 +00:00 (Migrated from github.com)

Summary by CodeRabbit

  • Chores
    • Reorganized CI/CD quality gate workflows to independently verify desktop and mobile app changes for streamlined continuous integration processes.
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Reorganized CI/CD quality gate workflows to independently verify desktop and mobile app changes for streamlined continuous integration processes. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
coderabbitai[bot] commented 2026-06-11 17:50:22 +00:00 (Migrated from github.com)

Review Change Stack

📝 Walkthrough

Walkthrough

The PR separates the PR quality gate workflows by platform: the desktop workflow is narrowed to desktop-only changes, and a new mobile-specific workflow is created to enforce the same lint and format checks for mobile code independently.

Changes

Platform-specific CI workflows

Layer / File(s) Summary
Separate desktop and mobile quality gate workflows
.github/workflows/pr-quality-gate-desktop.yml, .github/workflows/pr-quality-gate-mobile.yml
Desktop workflow refactored to trigger only on js/desktop/** changes with a single verify job; new mobile workflow created to independently enforce yarn lint and yarn format:check on js/mobile/** changes, both using Node.js 20 with immutable dependency installation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Poem

🐰 Workflows split clean, like a path through the wood,
Desktop and mobile, each does its own good,
Quality gates stand guard on their respective ways,
Lint and format checks through all of our days! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'ci: split pr quality gates for mobile and desktop' accurately and concisely describes the main change in the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-pr-quality-gates

Comment @coderabbitai help to get the list of available commands and usage tips.

<!-- This is an auto-generated comment: summarize by coderabbit.ai --> <!-- review_stack_entry_start --> [![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/flowy-live/llink/pull/268?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- walkthrough_start --> <details> <summary>📝 Walkthrough</summary> ## Walkthrough The PR separates the PR quality gate workflows by platform: the desktop workflow is narrowed to desktop-only changes, and a new mobile-specific workflow is created to enforce the same lint and format checks for mobile code independently. ## Changes **Platform-specific CI workflows** |Layer / File(s)|Summary| |---|---| |**Separate desktop and mobile quality gate workflows** <br> `.github/workflows/pr-quality-gate-desktop.yml`, `.github/workflows/pr-quality-gate-mobile.yml`|Desktop workflow refactored to trigger only on `js/desktop/**` changes with a single `verify` job; new mobile workflow created to independently enforce `yarn lint` and `yarn format:check` on `js/mobile/**` changes, both using Node.js 20 with immutable dependency installation.| ## Estimated code review effort 🎯 2 (Simple) | ⏱️ ~8 minutes ## Poem > 🐰 Workflows split clean, like a path through the wood, > Desktop and mobile, each does its own good, > Quality gates stand guard on their respective ways, > Lint and format checks through all of our days! ✨ </details> <!-- walkthrough_end --> <!-- pre_merge_checks_walkthrough_start --> <details> <summary>🚥 Pre-merge checks | ✅ 5</summary> <details> <summary>✅ Passed checks (5 passed)</summary> | Check name | Status | Explanation | | :------------------------: | :------- | :--------------------------------------------------------------------------------------------------------------------------------- | | Description Check | ✅ Passed | Check skipped - CodeRabbit’s high-level summary is enabled. | | Title check | ✅ Passed | The title 'ci: split pr quality gates for mobile and desktop' accurately and concisely describes the main change in the changeset. | | Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. | | Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. | | Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. | </details> <sub>✏️ Tip: You can configure your own custom pre-merge checks in the settings.</sub> </details> <!-- pre_merge_checks_walkthrough_end --> <!-- finishing_touch_checkbox_start --> <details> <summary>✨ Finishing Touches</summary> <details> <summary>🧪 Generate unit tests (beta)</summary> - [ ] <!-- {"checkboxId": "f47ac10b-58cc-4372-a567-0e02b2c3d479", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} --> Create PR with unit tests - [ ] <!-- {"checkboxId": "6ba7b810-9dad-11d1-80b4-00c04fd430c8", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} --> Commit unit tests in branch `fix-pr-quality-gates` </details> </details> <!-- finishing_touch_checkbox_end --> <!-- tips_start --> --- <sub>Comment `@coderabbitai help` to get the list of available commands and usage tips.</sub> <!-- tips_end --> <!-- internal state start --> <!-- DwQgtGAEAqAWCWBnSTIEMB26CuAXA9mAOYCmGJATmriQCaQDG+Ats2bgFyQAOFk+AIwBWJBrngA3EsgEBPRvlqU0AgfFwA6NPEgQAfACgjoCEejqANiS4N4XRNwvqefAI7Y0T3PKLVpkADN8PmZBeCt0DHolRABrAm4DADlsZgFKLgAmADYADgMAVQAlABkuWFxcbkQOAHpaonVYbAENJmZagIt8AHdZMCcpWosnDFja7mwR2pz8gsQMyFxPWMR4WIMAZXxsCgYSSAEqDAZYLgD4AA8wXjB3T3V+3xpEA2g0ClJcQ+PTrmZtBgtstcNgavxuGQDEUSBJ4CQepRwQYSioSBZkQBhCgkPz0ahZAAMOTAhOyYAAjBToBSAOwcAAsAE4OBSmQAtIz6YzgKBkej4AI4AjEMjKGj0dpsDCcFz8YSicRSGTyJhKKiqdRaHTckxQOCoVCYYWEUjkKgShSsdhcKg9SCIVIAijyOQKdUqNSabS6MCGHmmAwaRq4ZoCWo9YKxLq9RATCh3DxeJ5+MAxeL4bgaWTMCwcAwAIiLBgAxCXIABBACSovNeIdTo+8kFjFgmFIr0K3Fo9dDBwA4uoABItStieD4DDIAAKRUg92TkGeB0jFGj3XtBEC+AYYP4GAszawfcg6YS6G43C4J9X696kAwaDYkXoAANJxpJiMAPo49zSTRuGoWBEFfB972WT4SG+V8hDjM9M1qAAqJCwIACloChM24eAMCISBYLjUI1CsZDUIASg0GBYAOIRBAdXAKGwMRdhXNBkFOds6AdfAlhoyBbxje0MHvJQLnIZA0AdXCiAiV8pAoeAAlkMC6IESA0NwxAaDQAUhQWICLQOV9iPCEgwMwN8EO4VTBEQciABoBIQCJYhIEgcLwviDmsyBRlwWpvEhU5RHGIIKABb5tI85BsCiSg+OoBQp3wJwe0tNSNCMIwy0rCwaAtCcpyWXiTyUBgLA+agiuQFsSEubhgktYIeBaJwGEgdh1HhTsoCSScSGynLywAWUwJSAMgAAxMzK0fQ8AC9KCMEpcP8Ti8LoLgAGpMlqMAAGYKSMABRbT4Ei7i1QOHE4QRTqAnC2URroeBUkLYsDAgMAjGDJoWgjKMhLjW4F0eYhU1Mqxs1zfMiwLUty2rWtxW4x1WCbfghQ2jsjArWglHxB97sHXAR3Uitx0nZBBI3B8n24lDABwCWdIAARSTR5IH7PwNJGsIrHIwBcAhQxLvkY+AiFIChaqwV8vwsX8SH/bSwNhdhkDQ99IXIWhXyc19EFkE5YCwjB4CW/WCJxTMxT18jtz4WdkEgr4ZIIgFcIsqI/Iu9RuK3HH/Di9UCLg2ooZIMjXyouAVyBumxLWyTpLwuSFKUlTIDUsXW1C2q8G8yAcUapyFlwWLuEgFD+qUDQ4MgTJCRQpyyBUKxkBQpgS7QBhYhblAp2WEZkCUHWlBOHqBKaAjZA+LAtOHixfQu5g8Hb8zB7DoiBfMpzLOLuLkFfOeKCwfywKCEZem4t0T/nx3Io4EK+5jobcorfLxRqkqi/KyrCrUyxp1BqTVuItUmAIdqnUZTdWkEYfq5AsoomTq2LitAdoHVpPtQkp1zqXUlIoG6sJ4T2hII9JqXAXq0DeswD6CMvp+gDHyH2LY0B4FNGKIyhDrQyltGge06NnSulVEQjUXptS+kMHqaihpJJYHYSKM0qMeHSllEoZYZlCFKEON0PuDYMYumLlxFU7plCam9DqJhBgADaABvAsxxSBVloAWDgjiuLfmyEyEgABWTIuR9jZFEAEAsDkCxAVDG4gsf1QwA1prGeMiYHjeAhjQNM0gMxZhzBYMJBZtIfFwKtcgbiKThP5MUkgpSyn5MbC6aJccBIJ16IATAIXaZgGOrZebBljpSkgfCWUskQCUoAcIO9AtxSWsmASch5ICs2XBpeWwFwTh2stHRyL4i6wTsmBBYVMsA9HYsXACTEWI4gmbxMEBwpJrDTsZDOylbLqUXriPSRdeAkJ2MgNe+V4BgBzuXbAVdQxJVwhVbAhN0Cnlegweskds6CA0Hk66AAhPRsRMQsEcPVR40S2A0NSAWAAvg5BxTiSAuOiRS78AQmRoDJISWkuRaQkGyL4vJkTYDRNiWGQGa5gZJLBqk5cYBI4w1yeEgpFAilrVKeUqIlS3FYKlXU2Q0SqwyiwrQZi/gpLkHtJiKsTSBV03CpABFztc5MWKrhbeEdd5W0Xp4DEMLx5kFsP4Ve68oGyH3j7Mg4V9jIH8u7A+4VIriC8i/VY+4TlWAkJgb4CsTkq2+OrGUiBkXhLRRirFzAcWXDxe4jcJKAC6zCYHvMUZwuslopQ2hhZoqw2iDhQJ3LEAxwjjGbVMddcRWofS6l5FaZg6hvzwFoIgJWd1ES0G/NK743IDAyMJL4/YTdchoC3YSBkB1fG0FpLQBkaA6UE23QwBghI4V5FpJkEghIDpMkyB1ZdMipTjsndO26pC6Dfn5FIldI7PnfjYFBb8Mbp2LsAwYOxBhICQALEgWc6KO10HzWo6c+BoquPOJ4BYDl4OIaQAAeQUopAmZA3GBHwyQQjCGCy0B3NpRSeEsUKTQM4mUlB5qbBBFUrgdjSVEYLNdIonp1AAHUsI0GnBQcwuArDUYCLR+jiHECwB2BYWgqG+6zmU6pkTNDaBFDigAER3Hx1jRBECYhon3ajjFsB0aM5O0zGAFNWDs6FRzTEXMMeM+5sz0gGCKW4OISc3mHN4YxP5xDow3K0CrIgR00grPUaLGpgslVtJRdiDCR0+VEDUZsURhDcGEOVcQzGpIDMMvBcQKF+A4WiqQDy2EsrlX8kgjBL55zamqsFnqo4TA1VJwZbyw6WIzXIT0CgFipQ4mLFtMgAgIgsBOlSGXkIzGqA25QLoNmzrDHQhKAy0cs+MkOtVYY8ESWuFPB5dq2wDLMQmstfG514TVWKs3dE/Z2Iz2BOIc82MgH12/sFNBMV68fmBtdeG5VR8EWMAZcaeIRTBwADkth7COGcLwecnNvBLj8Mgc1CKD7WSx+gS9uw/BzIPkwSeCw5lvcUukF2/FPZYCDlvE8Qdy5HZu4h07wOCwXfNnhCHg2cTM4uEQViBnYvw9u4pRo80nt1a4AWDHSmvvw9+4Nmr2vEMWYYCx927HlCkBl11qHvXYf9eO4hxHo2UcZf6oEOKBzyc7B9nagXbZNr0AuB3X+sJPAeBoKeZjEto34A46QKimxpuXndkxi38f8JMCT2D0Kwu/s4kQKlPARUMvSf9rHrP1m/d8BPAEH3KOflIDufhPszBf6IGqogZSRdc824OKGYvmntOF8G2L8788ruq8Q3djXj2AdA9e3H2vCMqvfcq0brrJuXs6+KYlyAyXUscXB7P7r1BHdLDhy7obDUkdjdRzrybcQZu31EOwhY4FfZjG4q35zNMoy24IcjsfEqAKaf4ABmgduJ2RCU+l20u5+8+D2FgWue+8WuEiWx+ABFYKW0giAai6+lWm+5Wt+u+4uJGhcLYmwTAkIbWweHYecDm5+DuMO1+zuIud+I2yO5ez+AOU2b+9A6QcK1y3+CWf+KWABIyOIwBPs5qoY4BUwy8kBAE4+XWk+OukuM+t+yBmuS+puBYOwuAJGAQNBtsdmJiuBCwKWhBX2RGZaWWOWuAs4oOGWmQtIAgN6TIDAtAFIDITKDIW6uQtAB0uQAQV6viuQmQB0AgPiR0AQhIAguQTIwRbICRaA0RzIaAvi9KIR2QPYWRuQ/i2QCMxKlaIGYGpAEGAO06AGw6EAJo34QE1yC6/GrRhSMGDiTh04n+dAFYuAMIs66GLAY6uAWKcUuAbihIZRQGDRNaTRvR7RNA/6Ps9RUAuEBU80SxJAM6SARU7RMqnREuikNAVK7ihIbIJAAgR6B0YA+wfhYAtI+6AgYA26R6aY2QAgaA5CAQuQAgFxDAJKlaGxPGng2xuxawk4Kxc2foQAA== --> <!-- internal state end -->
coderabbitai[bot] (Migrated from github.com) reviewed 2026-06-11 17:56:15 +00:00
coderabbitai[bot] (Migrated from github.com) left a comment

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/pr-quality-gate-mobile.yml:
- Around line 19-25: Replace mutable action tags actions/checkout@v4 and
actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false
on the checkout step to reduce supply-chain and token exposure risk; update the
checkout step (actions/checkout) to include persist-credentials: false and
replace both uses entries (actions/checkout and actions/setup-node) with their
specific commit SHAs (use the official SHAs for the versions currently
referenced) so the workflow references immutable commits.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c764ac6d-9a10-4f74-8aa6-42ef51a52823

📥 Commits

Reviewing files that changed from the base of the PR and between 95f2362947 and 05ce208a8a.

📒 Files selected for processing (2)
  • .github/workflows/pr-quality-gate-desktop.yml
  • .github/workflows/pr-quality-gate-mobile.yml
**Actionable comments posted: 1** <details> <summary>🤖 Prompt for all review comments with AI agents</summary> ``` Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. Inline comments: In @.github/workflows/pr-quality-gate-mobile.yml: - Around line 19-25: Replace mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false on the checkout step to reduce supply-chain and token exposure risk; update the checkout step (actions/checkout) to include persist-credentials: false and replace both uses entries (actions/checkout and actions/setup-node) with their specific commit SHAs (use the official SHAs for the versions currently referenced) so the workflow references immutable commits. ``` </details> <details> <summary>🪄 Autofix (Beta)</summary> Fix all unresolved CodeRabbit comments on this PR: - [ ] <!-- {"checkboxId": "4b0d0e0a-96d7-4f10-b296-3a18ea78f0b9"} --> Push a commit to this branch (recommended) - [ ] <!-- {"checkboxId": "ff5b1114-7d8c-49e6-8ac1-43f82af23a33"} --> Create a new PR with the fixes </details> --- <details> <summary>ℹ️ Review info</summary> <details> <summary>⚙️ Run configuration</summary> **Configuration used**: defaults **Review profile**: CHILL **Plan**: Pro Plus **Run ID**: `c764ac6d-9a10-4f74-8aa6-42ef51a52823` </details> <details> <summary>📥 Commits</summary> Reviewing files that changed from the base of the PR and between 95f2362947076cea50ee50ef615e654ef1e0d45c and 05ce208a8a0435d7d4af9dda8cc0ca6872e0392c. </details> <details> <summary>📒 Files selected for processing (2)</summary> * `.github/workflows/pr-quality-gate-desktop.yml` * `.github/workflows/pr-quality-gate-mobile.yml` </details> </details> <!-- This is an auto-generated comment by CodeRabbit for review status -->
@@ -0,0 +22,4 @@
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
coderabbitai[bot] (Migrated from github.com) commented 2026-06-11 17:56:15 +00:00

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"

# Show file with line numbers around the referenced area
nl -ba "$FILE" | sed -n '1,120p'

# Also scan for other uses of actions/checkout and actions/setup-node in the repo for consistency
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

Repository: flowy-live/llink

Length of output: 103


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"
if [ ! -f "$FILE" ]; then
  echo "Missing file: $FILE"
  exit 1
fi

nl -ba "$FILE" | sed -n '1,160p'

echo "---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

echo "---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows || true

Repository: flowy-live/llink

Length of output: 104


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"
nl -ba "$FILE" | sed -n '1,200p'

echo "---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

echo "---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows || true

Repository: flowy-live/llink

Length of output: 103


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/pr-quality-gate-mobile.yml"

echo "=== pr-quality-gate-mobile.yml (lines 1-200) ==="
if [ -f "$FILE" ]; then
  cat -n "$FILE" | sed -n '1,200p'
else
  echo "Missing $FILE"
  exit 1
fi

echo "=== other workflows using checkout/setup-node (pinned or tag refs) ==="
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true

echo "=== persist-credentials occurrences ==="
rg -n "persist-credentials" .github/workflows || true

Repository: flowy-live/llink

Length of output: 1941


Pin actions to commit SHAs and disable persisted checkout credentials in CI

.github/workflows/pr-quality-gate-mobile.yml uses mutable tag refs (actions/checkout@v4 at line 20, actions/setup-node@v4 at line 23) and the checkout step does not set persist-credentials: false, increasing supply-chain and token exposure risk.

Suggested hardening diff
       - name: Check out repository code
-        uses: actions/checkout@v4
+        uses: actions/checkout@<FULL_COMMIT_SHA>
+        with:
+          persist-credentials: false

       - name: Set up Node.js
-        uses: actions/setup-node@v4
+        uses: actions/setup-node@<FULL_COMMIT_SHA>
         with:
           node-version: '20'
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 19-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/pr-quality-gate-mobile.yml around lines 19 - 25, Replace
mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned
commit SHAs and set persist-credentials: false on the checkout step to reduce
supply-chain and token exposure risk; update the checkout step
(actions/checkout) to include persist-credentials: false and replace both uses
entries (actions/checkout and actions/setup-node) with their specific commit
SHAs (use the official SHAs for the versions currently referenced) so the
workflow references immutable commits.

Source: Linters/SAST tools

_⚠️ Potential issue_ | _🟠 Major_ <details> <summary>🧩 Analysis chain</summary> 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" # Show file with line numbers around the referenced area nl -ba "$FILE" | sed -n '1,120p' # Also scan for other uses of actions/checkout and actions/setup-node in the repo for consistency rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 103 --- 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" if [ ! -f "$FILE" ]; then echo "Missing file: $FILE" exit 1 fi nl -ba "$FILE" | sed -n '1,160p' echo "---- other workflows using checkout/setup-node ----" rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true echo "---- check for persist-credentials usage ----" rg -n "persist-credentials" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 104 --- 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" nl -ba "$FILE" | sed -n '1,200p' echo "---- other workflows using checkout/setup-node ----" rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true echo "---- check for persist-credentials usage ----" rg -n "persist-credentials" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 103 --- 🏁 Script executed: ```shell #!/bin/bash set -euo pipefail FILE=".github/workflows/pr-quality-gate-mobile.yml" echo "=== pr-quality-gate-mobile.yml (lines 1-200) ===" if [ -f "$FILE" ]; then cat -n "$FILE" | sed -n '1,200p' else echo "Missing $FILE" exit 1 fi echo "=== other workflows using checkout/setup-node (pinned or tag refs) ===" rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true echo "=== persist-credentials occurrences ===" rg -n "persist-credentials" .github/workflows || true ``` Repository: flowy-live/llink Length of output: 1941 --- </details> **Pin actions to commit SHAs and disable persisted checkout credentials in CI** `.github/workflows/pr-quality-gate-mobile.yml` uses mutable tag refs (`actions/checkout@v4` at line 20, `actions/setup-node@v4` at line 23) and the checkout step does not set `persist-credentials: false`, increasing supply-chain and token exposure risk. <details> <summary>Suggested hardening diff</summary> ```diff - name: Check out repository code - uses: actions/checkout@v4 + uses: actions/checkout@<FULL_COMMIT_SHA> + with: + persist-credentials: false - name: Set up Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@<FULL_COMMIT_SHA> with: node-version: '20' ``` </details> <details> <summary>🧰 Tools</summary> <details> <summary>🪛 zizmor (1.25.2)</summary> [warning] 19-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) --- [error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) --- [error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) </details> </details> <details> <summary>🤖 Prompt for AI Agents</summary> ``` Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/pr-quality-gate-mobile.yml around lines 19 - 25, Replace mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false on the checkout step to reduce supply-chain and token exposure risk; update the checkout step (actions/checkout) to include persist-credentials: false and replace both uses entries (actions/checkout and actions/setup-node) with their specific commit SHAs (use the official SHAs for the versions currently referenced) so the workflow references immutable commits. ``` </details> <!-- fingerprinting:phantom:poseidon:hawk --> <!-- cr-comment:v1:d1e53b8162f207c4b8c489fe --> _Source: Linters/SAST tools_ <!-- This is an auto-generated comment by CodeRabbit -->
Sign in to join this conversation.