Skip to content

Run the widget gallery from CI rather than workflow_run - #578

Merged
matt-edmondson merged 1 commit into
mainfrom
claude/gallery-regen-workflow-1jkca0
Oct 1, 2026
Merged

matt-edmondson merged 1 commit into
mainfrom
claude/gallery-regen-workflow-1jkca0

Conversation

@matt-edmondson

Copy link
Copy Markdown
Contributor

Before: the widget gallery ran as a workflow_run workflow after CI. workflow_run runs with the repository's token after every CI run, including one started by a fork's pull request. SonarCloud flags that as githubactions:S7631 (forked code checked out in a privileged context), which failed main's quality gate with a C security rating and skipped the release.

After: the gallery is a reusable workflow. ci.yml calls it as a widget-gallery job that needs the pipeline, and only for a push to main. It can also be dispatched by hand on main. Both of those need write access, so nothing a fork wrote is ever checked out or built with the job's contents: write.

How:

  • widget-gallery.yml now triggers on workflow_call and workflow_dispatch. Its job is gated on the ktsu-dev/ImGuiApp repository and refs/heads/main.
  • Concurrency moved to the job, because a called workflow reports its caller's name.
  • The job still waits for the whole pipeline, release commit included, so the race Regenerate the widget gallery after CI rather than on the push #564 fixed stays fixed. A failed pipeline skips the gallery, as before.
  • CLAUDE.md now says not to go back to workflow_run.

actionlint passes on both workflows.

🤖 Generated with Claude Code

https://claude.ai/code/session_01UAiQ9k8PXay5udWkN4vi3U


Generated by Claude Code

SonarCloud failed main's quality gate on githubactions:S7631: a
workflow_run workflow runs with the repository's token and secrets after
any CI run, a fork's pull request included, so building checked-out code
there is a privileged context untrusted code could reach. The gallery
always checked out main, but the trigger itself is the risk the rule
names.

The gallery is now a reusable workflow that ci.yml calls as a job needing
the pipeline, only for a push to main. Only a push to main or a manual
dispatch on main can start it, and both need write access, so nothing a
fork wrote is ever built with its permissions. Ordering after the release
commit is unchanged, since the job still waits for the whole pipeline.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UAiQ9k8PXay5udWkN4vi3U
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants