What changed, and why it matters
This commit updates the GitHub Actions workflow that publishes documentation to GitHub Pages. It replaces a third-party deployment action with GitHub's official actions and adds explicit permissions so the workflow only gets the access it needs. The change is a routine hardening/improvement of the documentation publishing pipeline, not a fix for an active security flaw in the Monero Light Wallet Server software itself.
No urgent action required. Review the new workflow runs successfully and confirm the docs site deploys. Consider pinning the first-party actions to commit SHAs for supply-chain consistency, though version tags are already used.
Security signals we found
Workflow permissions narrowed to least-privilege (contents:read, pages:write, id-token:write)
Third-party action (peaceiris/actions-gh-pages) replaced with first-party GitHub Pages actions
No application code changed; only CI/CD documentation deployment pipeline affected
Evidence from the diff
The diff rewrites .github/workflows/deploy-pages.yml. Key changes: (1) adds top-level permissions limiting the workflow to contents: read, pages: write, id-token: write; (2) splits the job into a build job and a deploy job using actions/configure-pages, actions/upload-pages-artifact, and actions/deploy-pages; (3) removes the use of peaceiris/actions-gh-pages and the explicit GITHUB_TOKEN secret. These are best-practice improvements for GitHub Pages deployment. There is no code change to the Monero LWS application, no mention of a vulnerability, CVE, or security bug, and no attribution to a researcher.
Changed components
.github/workflows/deploy-pages.ymlInspect captured patch +30 / −18
diff --git a/.github/workflows/deploy-pages.yml b/.github/workflows/deploy-pages.yml
index e92fceb..98a44d9 100644
--- a/.github/workflows/deploy-pages.yml
+++ b/.github/workflows/deploy-pages.yml
@@ -1,27 +1,39 @@
name: docs
-
on:
push:
branches: [ "master" ]
paths: [ "docs/**", "mkdocs.yml" ]
-
+permissions:
+ contents: read
+ pages: write
+ id-token: write
jobs:
- deploy:
+ build:
+ environment:
+ name: github-pages
+ url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-latest
steps:
- - name: Checkout LWS Source
- uses: actions/checkout@v4
- - name: Setup Python
- uses: actions/setup-python@v6
- - name: Install dependencies
- run: |
- python3 -m pip install --upgrade pip
- python3 -m pip install mkdocs
- python3 -m pip install mkdocs-swagger-ui-tag
- python3 -m pip install mkdocs-schema-reader
- mkdocs build
- - name: Deploy
- uses: peaceiris/actions-gh-pages@v4
+ - uses: actions/configure-pages@v5
+ - uses: actions/checkout@v5
+ - uses: actions/setup-python@v5
+ with:
+ python-version: 3.x
+ - run: |
+ python3 -m pip install mkdocs
+ python3 -m pip install mkdocs-swagger-ui-tag
+ python3 -m pip install mkdocs-schema-reader
+ - uses: actions/upload-pages-artifact@v4
+ id: deployment
with:
- github_token: ${{ secrets.GITHUB_TOKEN }}
- publish_dir: ./site
+ path: site
+ deploy:
+ environment:
+ name: github-pages
+ url: ${{ steps.deployment.outputs.page_url }}
+ runs-on: ubuntu-latest
+ needs: build
+ steps:
+ - name: Deploy to GitHub Pages
+ id: deployment
+ uses: actions/deploy-pages@v4
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.