mirror of
https://github.com/react/react-native.git
synced 2026-09-29 16:58:04 +08:00
Summary: Pins the default `GITHUB_TOKEN` to `contents: read` on 2 workflows in `.github/workflows/` that don't call a GitHub API beyond the initial checkout. The following files were left implicit because they reference `GITHUB_TOKEN` / use a write-scope action / trigger on `pull_request_target`. Those scopes are best declared by maintainers: `cache-reaper.yml`, `check-for-reproducer.yml`, `retry-workflow.yml`, `validate-dotslash-artifacts.yml`. ## Why CVE-2025-30066 (March 2025 `tj-actions/changed-files` supply-chain compromise) exfiltrated `GITHUB_TOKEN` from workflow logs. Pinning per workflow caps runtime authority irrespective of the repo or org default, gives drift protection if the default ever widens, and is credited per-file by the OpenSSF Scorecard `Token-Permissions` check. YAML validated locally with `yaml.safe_load` on each touched file. ## Changelog [Internal] [Changed] - Pull Request resolved: https://github.com/facebook/react-native/pull/56834 Reviewed By: cipolleschi Differential Revision: D105294446 Pulled By: cortinico fbshipit-source-id: c90e885345f7b49d6c3ccfd73fdbd7ce8eebe4a1
86 lines
2.7 KiB
YAML
86 lines
2.7 KiB
YAML
name: Validate C++ API Snapshots
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
pull_request:
|
|
paths:
|
|
- "packages/react-native/ReactCommon/**"
|
|
- "packages/react-native/ReactAndroid/**"
|
|
- "packages/react-native/React/**"
|
|
- "packages/react-native/ReactApple/**"
|
|
- "packages/react-native/Libraries/**"
|
|
- "scripts/cxx-api/**"
|
|
push:
|
|
branches:
|
|
- main
|
|
- "*-stable"
|
|
paths:
|
|
- "packages/react-native/ReactCommon/**"
|
|
- "packages/react-native/ReactAndroid/**"
|
|
- "packages/react-native/React/**"
|
|
- "packages/react-native/ReactApple/**"
|
|
- "packages/react-native/Libraries/**"
|
|
- "scripts/cxx-api/**"
|
|
|
|
env:
|
|
DOXYGEN_VERSION: "1.16.1"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
validate_cxx_api_snapshots:
|
|
runs-on: ubuntu-latest
|
|
if: github.repository == 'facebook/react-native'
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
- name: Setup node.js
|
|
uses: ./.github/actions/setup-node
|
|
- name: Run yarn
|
|
uses: ./.github/actions/yarn-install
|
|
- name: Restore Doxygen cache
|
|
id: cache-doxygen
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: /tmp/doxygen-${{ env.DOXYGEN_VERSION }}
|
|
key: doxygen-${{ env.DOXYGEN_VERSION }}
|
|
- name: Install Doxygen
|
|
if: steps.cache-doxygen.outputs.cache-hit != 'true'
|
|
shell: bash
|
|
run: |
|
|
DOXYGEN_URL="https://github.com/doxygen/doxygen/releases/download/Release_${DOXYGEN_VERSION//./_}/doxygen-${DOXYGEN_VERSION}.linux.bin.tar.gz"
|
|
MAX_RETRIES=3
|
|
for i in $(seq 1 $MAX_RETRIES); do
|
|
echo "Attempt $i of $MAX_RETRIES: Installing Doxygen ${DOXYGEN_VERSION}..."
|
|
curl -fsSL "$DOXYGEN_URL" -o /tmp/doxygen.tar.gz && \
|
|
tar -xzf /tmp/doxygen.tar.gz -C /tmp && \
|
|
echo "Doxygen installed successfully." && \
|
|
break
|
|
echo "Attempt $i failed."
|
|
if [ $i -eq $MAX_RETRIES ]; then
|
|
echo "All $MAX_RETRIES attempts failed."
|
|
exit 1
|
|
fi
|
|
sleep 5
|
|
done
|
|
- name: Set DOXYGEN_BIN
|
|
shell: bash
|
|
run: echo "DOXYGEN_BIN=/tmp/doxygen-${DOXYGEN_VERSION}/bin/doxygen" >> "$GITHUB_ENV"
|
|
- name: Set up Python
|
|
uses: actions/setup-python@v5
|
|
with:
|
|
python-version: "3.12"
|
|
- name: Install Python dependencies
|
|
shell: bash
|
|
run: pip install doxmlparser natsort pyyaml
|
|
- name: Validate C++ API snapshots
|
|
shell: bash
|
|
run: yarn cxx-api-validate --output-dir /tmp/cxx-api-snapshots
|
|
- name: Upload C++ API snapshots
|
|
if: always()
|
|
uses: actions/upload-artifact@v6
|
|
with:
|
|
name: cxx-api-snapshots
|
|
path: /tmp/cxx-api-snapshots/
|