-
Notifications
You must be signed in to change notification settings - Fork 8
Harden CI supply chain and add an org-wide security policy #275
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,47 @@ | ||
| # Security Policy | ||
|
|
||
| WP-CLI is used to administer WordPress sites in production, frequently with | ||
| elevated privileges, so we take security reports seriously. | ||
|
|
||
| This is the organization-wide default policy for repositories in the | ||
| [`wp-cli` organization](https://github.com/wp-cli). A repository that publishes | ||
| its own `SECURITY.md` overrides this one. | ||
|
|
||
| ## Reporting a vulnerability | ||
|
|
||
| **Please do not report security vulnerabilities through public GitHub issues, | ||
| pull requests, or discussions.** | ||
|
|
||
| Report them through the WordPress bug bounty program on HackerOne, which covers | ||
| WP-CLI alongside WordPress core and related projects: | ||
|
|
||
| <https://hackerone.com/wordpress> | ||
|
|
||
| Before you submit, please read the full guidance in the WP-CLI handbook: | ||
|
|
||
| <https://make.wordpress.org/cli/handbook/contributions/security-vulnerability-reporting/> | ||
|
|
||
| That handbook page is the authoritative description of what we treat as a | ||
| vulnerability, what to include in a report, and what to expect during | ||
| coordinated disclosure. A valid report may be eligible for a CVE and a bounty. | ||
|
|
||
| ## What makes a report actionable | ||
|
|
||
| A vulnerability report needs to show how someone outside a trust boundary gains | ||
| something they could not otherwise obtain. Please state plainly: | ||
|
|
||
| - who the attacker is and what access they begin with, | ||
| - what they gain that they should not have, | ||
| - the steps to reproduce it. | ||
|
|
||
| Reports that do not demonstrate an actual exploit are likely to be declined. | ||
| Note that WP-CLI runs as a trusted local user by design: someone who can already | ||
| execute `wp` on a server can generally already act as that user, so that alone | ||
| is not a privilege boundary. | ||
|
|
||
| ## Build and release infrastructure | ||
|
|
||
| Reports about this organization's shared CI configuration — the reusable | ||
| GitHub Actions workflows in [`wp-cli/.github`](https://github.com/wp-cli/.github) | ||
| and the credentials they use — are in scope and are best sent through the same | ||
| channel above. |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: wp-cli/.github
Length of output: 301
🏁 Script executed:
Repository: wp-cli/.github
Length of output: 10430
Pin and verify the WP-CLI PHAR before installation.
This workflow has write permissions, persists checkout credentials, and runs
wpdirectly. The download path still follows mutablegh-pagesand does not check a digest or signature before moving the PHAR to/usr/local/bin/wp. Use an immutable commit/tag reference and verify an out-of-band checksum or signature before installation.🤖 Prompt for AI Agents