unsloth/.github
Daniel Han 05d6a2f3ae
security: persist-credentials:false on every actions/checkout (org-wide sweep) (#5413)
## Threat model

When `actions/checkout` runs without `persist-credentials: false`,
the short-lived `GITHUB_TOKEN` injected at job start gets written
into the workspace's `.git/config` so subsequent Git operations
in the same job (push, fetch, etc.) can use it transparently.

Failure mode if a downstream step packages the workspace:

  1. Step T fetches the repo via `actions/checkout` (token in
     `.git/config`).
  2. Step T+N packages the workspace -- or `logs/`, or a `dist/`
     dir that lives inside the workspace -- via
     `actions/upload-artifact`. The hidden `.git/` folder rides
     along.
  3. While the workflow is still running, the uploaded zip is
     immediately downloadable via the GitHub UI / API. On a
     PUBLIC repo, any logged-in GitHub user can download it.
  4. The attacker extracts the live `GITHUB_TOKEN` from
     `.git/config` and uses it to push code, modify branches,
     comment on / close PRs, etc., before the token expires at
     end-of-workflow (typically 1-6 hours).

This is a moderate-risk class because our long-running workflows
(Studio inference smoke, full Tauri build, MLX install on macOS)
keep the token alive for 30+ minutes -- plenty of window.

## What changes

Adds `with: persist-credentials: false` to all 51
`actions/checkout` call sites across 23 workflows. None of our
workflows actually use the persisted credentials -- the only
push-back operations are `gh release create / upload` in
release-desktop.yml, and those go through `${{ secrets.GITHUB_TOKEN }}`
explicitly (NOT via the persisted .git/config token).

So the sweep is universal -- no exceptions, no broken push-paths,
no required follow-up.

## Verification

- 51 checkout calls / 51 persist-credentials lines (one-to-one).
- All 24 workflow YAMLs still parse cleanly under PyYAML.
- No push-back-via-persisted-creds call site exists -- grepped
  the workflow tree for `git push`, `git remote update`, etc.
  Zero matches outside intentional `gh release ...` calls that
  explicitly forward `${{ secrets.GITHUB_TOKEN }}`.

## Companion PR

unslothai/unsloth-zoo PR #637 (the greenfield CI mirror) gets the
same sweep on its 9 checkout sites in commit 1e6c0b0. Filed there
rather than as a separate PR to keep the related changes
together.
2026-05-13 22:02:35 -07:00
..
ISSUE_TEMPLATE Update issue template 2026-03-23 10:10:15 +05:30
workflows security: persist-credentials:false on every actions/checkout (org-wide sweep) (#5413) 2026-05-13 22:02:35 -07:00
CODEOWNERS security: NOT affected by Mini Shai-Hulud (May-12 wave) -- forward-looking hardening only (#5397) 2026-05-13 04:58:12 -07:00
dependabot.yml security: NOT affected by Mini Shai-Hulud (May-12 wave) -- forward-looking hardening only (#5397) 2026-05-13 04:58:12 -07:00
FUNDING.yml Update FUNDING.yml (#3792) 2025-12-28 19:57:43 -08:00