Pin GitHub Actions to commit SHAs - #27
Closed
henrybear327 wants to merge 1 commit into
Closed
henrybear327 wants to merge 1 commit into
henrybear327 wants to merge 1 commit into
Conversation
Every action was referenced by a floating major tag such as actions/checkout@v6. Such a tag is mutable, so whoever controls the action repository can repoint it at new code, which then runs in the release job with contents: write and pushes tags. A commit SHA cannot be repointed. The release version stays in a trailing comment so the reference is still readable, and so Dependabot can rewrite the SHA and the comment together. Move to the current majors in the same pass: checkout v6 to v7.0.1 and cache v5 to v6.1.0, both ESM and dependency refreshes. The new checkout v7 restriction on fork pull request checkout applies only to pull_request_target and workflow_run, which this workflow does not use.
Contributor
|
Don't do that. The deliverables are not security-oriented, so always use shorter, simpler notation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Improve CI security.
Every action was referenced by a floating major tag such as actions/checkout@v6. Such a tag is mutable, so whoever controls the action repository can repoint it at new code, which then runs in the release job with contents: write and pushes tags. A commit SHA cannot be repointed.
The release version stays in a trailing comment so the reference is still readable, and so Dependabot can rewrite the SHA and the comment together.
Summary by cubic
Pin all GitHub Actions in
.github/workflows/main.ymlto commit SHAs and upgrade to current majors to harden CI. This removes mutable tags, reduces supply-chain risk, and keeps readable version comments so Dependabot can auto-update.actions/checkoutpinned to3d3c42e5aac5ba805825da76410c181273ba90b1(v7.0.1)actions/cachepinned to55cc8345863c7cc4c66a329aec7e433d2d1c52a9(v6.1.0)actions/upload-artifactpinned to043fb46d1a93c77aae656e7c1c64a875d1fc6a0a(v7.0.1)actions/download-artifactpinned to3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c(v8.0.1)softprops/action-gh-releasepinned to3d0d9888cb7fd7b750713d6e236d1fcb99157228(v3.0.2)Written for commit 9991939. Summary will update on new commits.