Skip to content

revert(ci): restore auto-deploy for the LNbits droplet - #261

Merged
ralyodio merged 1 commit into
masterfrom
fix/restore-lnbits-autodeploy
Aug 16, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/restore-lnbits-autodeploy

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Restores continuous deployment on push to master, reverting the approval gate #260 added for audit finding N-020.

Continuous deployment here is a deliberate trade-off and it's yours to make, not the audit's. The workflow comment records that, and records how to put the gate back in two lines if you ever want it.

Not reverted (separate findings, not asked for):

  • P-018 — ENV_FILE and DIRECT_SSH_KEY still read from secrets only. They used to fall back to vars.*, and Actions variables are plaintext, readable by anyone with repo access, and not masked in job logs — an SSH private key supplied that way would be printed in the clear.
  • actions/checkout stays pinned to its commit SHA.

Verified: only the trigger and the environment: key changed; zero live vars.* references remain.

🤖 Generated with Claude Code

#260 changed this workflow to workflow_dispatch-only under a "production"
environment, to satisfy audit finding N-020 (SSH deploy without an approval
gate). That removed continuous deployment, which is behaviour the maintainer
relies on. Reverted at their request.

Continuous deployment here is a deliberate trade-off and it is the maintainer's
to make, not the audit's. The workflow comment records that, and records how to
put the gate back in two lines if that ever changes.

What is NOT reverted, because it was a separate finding and was not asked for:

  P-018 — ENV_FILE and DIRECT_SSH_KEY still read from `secrets` only. They used
  to fall back to `vars.*`, and GitHub Actions variables are plaintext,
  readable by anyone with repo access, and NOT masked in job logs; an SSH
  private key supplied that way would be printed in the clear.

  Action pinning — actions/checkout stays pinned to its commit SHA.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

327 finding(s)

HIGH/CRITICAL: 35 | MEDIUM: 38 | LOW: 254

Severity Rule Location
HIGH secret-private-key .env.example:236
HIGH secret-generic-api-key docs/API.md:430
HIGH secret-generic-api-key docs/API.md:585
HIGH secret-generic-credential docs/FIX_VERIFY_SIGNATURE.md:156
HIGH secret-generic-credential docs/integration-examples/nodejs-bot.md:225
HIGH secret-generic-api-key docs/sdk/getting-started.md:36
HIGH secret-generic-api-key docs/sdk/getting-started.md:318
HIGH sensitive-file-committed doppler.env:1
HIGH secret-generic-api-key packages/sdk/README.md:99
HIGH secret-generic-credential packages/sdk/README.md:122
HIGH secret-generic-credential packages/sdk/README.md:743
HIGH sh-remote-script-execution public/install.sh:142
HIGH sh-remote-script-execution public/install.sh:338
HIGH sh-remote-script-execution public/install.sh:342
HIGH sh-remote-script-execution public/install.sh:347
HIGH sh-remote-script-execution public/install.sh:351
HIGH sh-remote-script-execution public/install.sh:420
HIGH sh-remote-script-execution public/install.sh:656
HIGH sh-remote-script-execution public/install.sh:657
HIGH sh-remote-script-execution public/install.sh:697
HIGH sh-remote-script-execution public/install.sh:698
HIGH sh-remote-script-execution public/install.sh:699
HIGH secret-generic-credential scripts/setup-droplet.sh:609
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:135
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:214
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1001
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1022
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:1400
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1481
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1490
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:1532
HIGH secret-generic-credential src/components/docs/AuthenticationDocs.tsx:37
HIGH secret-generic-credential src/components/docs/OAuthDocs.tsx:262
HIGH secret-generic-credential supabase/config.toml:255
HIGH secret-generic-credential supabase/config.toml:287
MEDIUM manifest-install-lifecycle-script package.json:26
MEDIUM js-shell-exec-interpolation packages/sdk/bin/coinpay.js:40
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-issuer.test.js:23
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-reputation.test.js:23
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:22
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:33
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:48
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:63
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:78
MEDIUM js-shell-exec-interpolation packages/sdk/test/wallet-backup.test.js:82
MEDIUM js-shell-exec-interpolation packages/sdk/test/wallet.test.js:249
MEDIUM js-shell-exec-interpolation packages/sdk/test/wallet.test.js:280
MEDIUM insecure-temp-file public/install.sh:83
MEDIUM sh-unquoted-expansion-destructive public/install.sh:613
MEDIUM js-unescaped-html-sink public/payments.js:93

…and 277 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 0b3e74e into master Aug 16, 2026
9 checks passed
ralyodio added a commit that referenced this pull request Aug 19, 2026
#260 changed this workflow to workflow_dispatch-only under a "production"
environment, to satisfy audit finding N-020 (SSH deploy without an approval
gate). That removed continuous deployment, which is behaviour the maintainer
relies on. Reverted at their request.

Continuous deployment here is a deliberate trade-off and it is the maintainer's
to make, not the audit's. The workflow comment records that, and records how to
put the gate back in two lines if that ever changes.

What is NOT reverted, because it was a separate finding and was not asked for:

  P-018 — ENV_FILE and DIRECT_SSH_KEY still read from `secrets` only. They used
  to fall back to `vars.*`, and GitHub Actions variables are plaintext,
  readable by anyone with repo access, and NOT masked in job logs; an SSH
  private key supplied that way would be printed in the clear.

  Action pinning — actions/checkout stays pinned to its commit SHA.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant