Skip to content
This repository was archived by the owner on Jul 4, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from 6 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .envrc
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# shellcheck shell=bash
if ! has nix_direnv_version || ! nix_direnv_version 3.0.6; then
URL=https://raw.githubusercontent.com/nix-community/nix-direnv/3.0.6/direnvrc
HASH=sha256-RYcUJaRMf8oF5LznDrlCXbkOQrywm0HDv1VjYGaJGdM=
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/pr-assessment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,6 @@ on:
pull_request:
types:
- closed

jobs:
assess-pr-size-on-merge:
uses: rainlanguage/github-chore/.github/workflows/pr-assessment.yml@main
Expand Down
5 changes: 5 additions & 0 deletions .github/workflows/rainix-rs.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
name: rainix-rs
on: [push]
jobs:
rs:
uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Fetch the reusable workflow file to check documented permission requirements
gh api repos/rainlanguage/rainix/contents/.github/workflows/rainix-rs.yaml --jq '.download_url' | xargs curl -s | head -50

Repository: rainlanguage/alloy-ethers-typecast

Length of output: 367


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "=== Fetch rainix-rs reusable workflow (permissions occurrences) ==="
curl -sL "$(gh api repos/rainlanguage/rainix/contents/.github/workflows/rainix-rs.yaml --jq '.download_url')" \
  | rg -n "^(permissions:|  permissions:|\spermissions:)" || true

echo "=== Fetch nested reusable workflows and search for permissions ==="
for wf in rainix-rs-static rainix-rs-test rainix-rs-wasm rainix-rs-wasm-test; do
  url="$(gh api repos/rainlanguage/rainix/contents/.github/workflows/${wf}.yaml --jq '.download_url')"
  echo "--- ${wf}.yaml ---"
  curl -sL "$url" | rg -n "^(permissions:|  permissions:|\spermissions:)" || true
done

echo "=== Fetch first 120 lines of rainix-rs.yaml for context ==="
curl -sL "$(gh api repos/rainlanguage/rainix/contents/.github/workflows/rainix-rs.yaml --jq '.download_url')" | head -120

Repository: rainlanguage/alloy-ethers-typecast

Length of output: 681


🌐 Web query:

GitHub Actions reusable workflow job uses permissions: does called workflow inherit caller GITHUB_TOKEN permissions or its own permissions keyword

💡 Result:

When a reusable workflow is called, it inherits the permissions defined in the calling workflow's job [1][2][3]. Specifically: 1. Inheritance and Constraints: The called (reusable) workflow receives the GITHUB_TOKEN permissions defined in the calling job [2][3]. These permissions can only be downgraded (made more restrictive) by the called workflow; they cannot be elevated [2][3]. 2. Default Behavior: If the calling job does not explicitly define a permissions block, the called workflow uses the default GITHUB_TOKEN permissions [2][3]. 3. Interaction of Permissions: GitHub validates the call by comparing the caller job's declared permissions with the permissions requested by the nested jobs in the called workflow [4]. If the caller job does not grant the necessary permissions required by the called workflow, the workflow will fail validation before execution [4]. Because of this inheritance model, it is common practice to explicitly define permissions in both the caller (to set the available envelope) and the called workflow (to define the specific needs of that task, ensuring it does not exceed the caller's granted scope) [1][4].

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "=== Local .github/workflows/rainix-rs.yaml (lines 1-60) ==="
nl -ba .github/workflows/rainix-rs.yaml | sed -n '1,60p'

echo "=== Search for permissions keyword in local workflow ==="
rg -n "^\s*permissions:" .github/workflows/rainix-rs.yaml || true

Repository: rainlanguage/alloy-ethers-typecast

Length of output: 199


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "=== Local file exists? ==="
ls -la .github/workflows/rainix-rs.yaml

echo "=== Local .github/workflows/rainix-rs.yaml (head) ==="
sed -n '1,80p' .github/workflows/rainix-rs.yaml

echo "=== Search for top-level permissions keyword in local workflow ==="
rg -n "^\s*permissions:" .github/workflows/rainix-rs.yaml || true

echo "=== Search for any permissions keyword in local workflow ==="
rg -n "permissions:" .github/workflows/rainix-rs.yaml || true

Repository: rainlanguage/alloy-ethers-typecast

Length of output: 475


Add an explicit top-level permissions: block to enforce least-privilege for the reusable workflow call.

.github/workflows/rainix-rs.yaml has no permissions:, so the GITHUB_TOKEN used by the uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main job falls back to GitHub’s default (often overly broad) token scopes. Reusable workflows inherit those caller permissions, so this should be tightened in the caller.

🛡️ Proposed fix
 name: rainix-rs
 on: [push]
+permissions:
+  contents: read
 jobs:
   rs:
     uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
name: rainix-rs
on: [push]
jobs:
rs:
uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main
name: rainix-rs
on: [push]
permissions:
contents: read
jobs:
rs:
uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 1-6: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block

(excessive-permissions)


[error] 5-5: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/rainix-rs.yaml around lines 1 - 5, Add a top-level
permissions block in the rainix-rs GitHub Actions workflow file to explicitly
specify the minimum necessary permissions for the reusable workflow call. This
means adding a permissions field before the jobs section, defining allowed
permissions for the GITHUB_TOKEN to enforce least privilege according to the
needs of the reusable workflow used by the "rs" job.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Find the latest commit SHA on the main branch of rainlanguage/rainix
gh api repos/rainlanguage/rainix/commits/main --jq '.sha'

Repository: rainlanguage/alloy-ethers-typecast

Length of output: 119


Pin the reusable workflow reference to a commit SHA

.github/workflows/rainix-rs.yaml uses the reusable workflow via @main, which is non-reproducible and expands supply-chain risk. Pin it to a specific commit SHA (current rainlanguage/rainix@main: f22d4dcaca61717e33eac65e7b09b9a82f604c1f).

🔒 Proposed fix to pin to a commit SHA
-    uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main
+    uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@f22d4dcaca61717e33eac65e7b09b9a82f604c1f
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main
uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@f22d4dcaca61717e33eac65e7b09b9a82f604c1f
🧰 Tools
🪛 zizmor (1.25.2)

[error] 5-5: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/rainix-rs.yaml at line 5, Update the reusable workflow
reference so it is pinned to a commit SHA instead of the branch name; replace
the "uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main" reference
with the specific commit SHA provided (f22d4dcaca61717e33eac65e7b09b9a82f604c1f)
to ensure reproducible CI runs and reduce supply-chain risk.

47 changes: 0 additions & 47 deletions .github/workflows/rainix.yaml

This file was deleted.

4 changes: 2 additions & 2 deletions .vscode/settings.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
"editor.rulers": [80]
}
"editor.rulers": [80]
}
16 changes: 10 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,18 +1,22 @@
## Crate for Safe Typecasting between Ethers and Alloy types

Currently supporting type conversion for:
- `ethers::types::H160` to `alloy_primitives::Address`

- `ethers::types::H160` to `alloy_primitives::Address`
- `alloy_primitives::Address` to `ethers::types::H160`
- `ethers::types::U256` to `alloy_primitives::U256`
- `alloy_primitives::U256` to `ethers::types::U256`
- `ethers::types::Bytes` to `alloy_primitives::Bytes`
- `alloy_primitives::Bytes` to `ethers::types::Bytes`
- `ethers::types::U256` to `alloy_primitives::U256`
- `alloy_primitives::U256` to `ethers::types::U256`
- `ethers::types::Bytes` to `alloy_primitives::Bytes`
- `alloy_primitives::Bytes` to `ethers::types::Bytes`

## Example

```sh
let ethers_address: ethers::types::H160 = ethers::types::H160::random();
let alloy_address: alloy_primitives::Address = ethers_address_to_alloy(ethers_address);
```

```sh
let ethers_u256: ethers::types::U256 = ethers::types::U256::from_dec_str("126731272983");
let alloy_u256: alloy_primitives::U256 = ethers_u256_to_alloy(ethers_u256);
```
```
131 changes: 103 additions & 28 deletions flake.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 3 additions & 2 deletions flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,12 @@
description = "Flake for development workflows.";

inputs = {
rainix.url = "github:rainprotocol/rainix";
rainix.url = "github:rainlanguage/rainix";
flake-utils.url = "github:numtide/flake-utils";
};

outputs = { self, flake-utils, rainix }:
outputs =
{ flake-utils, rainix, ... }:
flake-utils.lib.eachDefaultSystem (system: {
packages = rainix.packages.${system};
devShells = rainix.devShells.${system};
Expand Down
Loading