You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
High – Supply chain risk from mutable reusable-workflow ref
Both workflows call external reusable workflows by tag (@v1.0.1) instead of an immutable commit SHA. If that tag is moved or compromised, arbitrary workflow code can run in this repo context with passed secrets.
High (conditional) – Secret exposure path via /issue_comment trigger
The job runs on issue_comment and passes API secrets. If the called reusable workflow checks out or executes PR-head code (especially from forks), a collaborator comment (/codex or /claude) could trigger secret exfiltration from attacker-controlled changes. The risk depends on callee workflow internals, but this PR introduces the exposure path.
Medium – No explicit token permission scoping
No permissions: block is set. This leaves GITHUB_TOKEN scope to repo/org defaults, which may be broader than required.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add Claude and Codex for code reviews
Description
Allow Claude and Codex to perform code reviews.
Type of change
Checklist
testnet, everything else tostaging