Repository navigation
chore: latest rainix + soldeer re-lock #61
Changes from 6 commits
ef59e5c
26d1977
eef8ed9
627cbd8
5f0d4f3
8ae7fef
398cc60
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -0,0 +1,5 @@ | ||||||
| name: rainix-rs | ||||||
| on: [push] | ||||||
| jobs: | ||||||
| rs: | ||||||
| uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
# Find the latest commit SHA on the main branch of rainlanguage/rainix
gh api repos/rainlanguage/rainix/commits/main --jq '.sha'Repository: rainlanguage/alloy-ethers-typecast Length of output: 119 Pin the reusable workflow reference to a commit SHA
🔒 Proposed fix to pin to a commit SHA- uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@main
+ uses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@f22d4dcaca61717e33eac65e7b09b9a82f604c1f📝 Committable suggestion
Suggested change
🧰 Tools🪛 zizmor (1.25.2)[error] 5-5: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI Agents |
||||||
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,3 @@ | ||
| { | ||
| "editor.rulers": [80] | ||
| } | ||
| "editor.rulers": [80] | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,18 +1,22 @@ | ||
| ## Crate for Safe Typecasting between Ethers and Alloy types | ||
|
|
||
| Currently supporting type conversion for: | ||
| - `ethers::types::H160` to `alloy_primitives::Address` | ||
|
|
||
| - `ethers::types::H160` to `alloy_primitives::Address` | ||
| - `alloy_primitives::Address` to `ethers::types::H160` | ||
| - `ethers::types::U256` to `alloy_primitives::U256` | ||
| - `alloy_primitives::U256` to `ethers::types::U256` | ||
| - `ethers::types::Bytes` to `alloy_primitives::Bytes` | ||
| - `alloy_primitives::Bytes` to `ethers::types::Bytes` | ||
| - `ethers::types::U256` to `alloy_primitives::U256` | ||
| - `alloy_primitives::U256` to `ethers::types::U256` | ||
| - `ethers::types::Bytes` to `alloy_primitives::Bytes` | ||
| - `alloy_primitives::Bytes` to `ethers::types::Bytes` | ||
|
|
||
| ## Example | ||
|
|
||
| ```sh | ||
| let ethers_address: ethers::types::H160 = ethers::types::H160::random(); | ||
| let alloy_address: alloy_primitives::Address = ethers_address_to_alloy(ethers_address); | ||
| ``` | ||
|
|
||
| ```sh | ||
| let ethers_u256: ethers::types::U256 = ethers::types::U256::from_dec_str("126731272983"); | ||
| let alloy_u256: alloy_primitives::U256 = ethers_u256_to_alloy(ethers_u256); | ||
| ``` | ||
| ``` |
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🧩 Analysis chain
🏁 Script executed:
Repository: rainlanguage/alloy-ethers-typecast
Length of output: 367
🏁 Script executed:
Repository: rainlanguage/alloy-ethers-typecast
Length of output: 681
🌐 Web query:
GitHub Actions reusable workflow job uses permissions: does called workflow inherit caller GITHUB_TOKEN permissions or its own permissions keyword💡 Result:
When a reusable workflow is called, it inherits the permissions defined in the calling workflow's job [1][2][3]. Specifically: 1. Inheritance and Constraints: The called (reusable) workflow receives the GITHUB_TOKEN permissions defined in the calling job [2][3]. These permissions can only be downgraded (made more restrictive) by the called workflow; they cannot be elevated [2][3]. 2. Default Behavior: If the calling job does not explicitly define a permissions block, the called workflow uses the default GITHUB_TOKEN permissions [2][3]. 3. Interaction of Permissions: GitHub validates the call by comparing the caller job's declared permissions with the permissions requested by the nested jobs in the called workflow [4]. If the caller job does not grant the necessary permissions required by the called workflow, the workflow will fail validation before execution [4]. Because of this inheritance model, it is common practice to explicitly define permissions in both the caller (to set the available envelope) and the called workflow (to define the specific needs of that task, ensuring it does not exceed the caller's granted scope) [1][4].
Citations:
permissions: {}to all reusable workflows python/cpython#148114call-workflowgenerated caller jobs omit requiredpermissions:for reusable workflows github/gh-aw#21071🏁 Script executed:
Repository: rainlanguage/alloy-ethers-typecast
Length of output: 199
🏁 Script executed:
Repository: rainlanguage/alloy-ethers-typecast
Length of output: 475
Add an explicit top-level
permissions:block to enforce least-privilege for the reusable workflow call..github/workflows/rainix-rs.yamlhas nopermissions:, so theGITHUB_TOKENused by theuses: rainlanguage/rainix/.github/workflows/rainix-rs.yaml@mainjob falls back to GitHub’s default (often overly broad) token scopes. Reusable workflows inherit those caller permissions, so this should be tightened in the caller.🛡️ Proposed fix
📝 Committable suggestion
🧰 Tools
🪛 zizmor (1.25.2)
[warning] 1-6: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[error] 5-5: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents