ci: pin third-party GitHub Actions to commit SHAs#357
Open
arpitjain099 wants to merge 1 commit into
Open
Conversation
Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two of the third-party actions in CI are referenced by floating refs, and
marvinpinto/action-automatic-releases@latestis the riskiest kind:latestresolves to whatever the maintainer last tagged, with zero review on our side, and it runs in the release workflow where the token has write access. golangci-lint-action is pinned to thev9major tag, which can also be moved.Floating refs are the exact vector behind CVE-2025-30066 (tj-actions/changed-files), where an attacker rewrote existing tags to point at credential-stealing commits. Pinning to a verified commit SHA means the runner only ever executes the code we looked at.
This change pins:
The tag name stays in a trailing comment for readability and future bumps. I deliberately left ci-build-image.yml alone because it is a reusable workflow (on: workflow_call), and skipped the GitHub-owned actions/* entries. Pins like these are what the OpenSSF Scorecard Pinned-Dependencies check looks for.