Skip to content

ci: pin third-party GitHub Actions to commit SHAs#357

Open
arpitjain099 wants to merge 1 commit into
containerd:mainfrom
arpitjain099:chore/pin-actions-sha
Open

ci: pin third-party GitHub Actions to commit SHAs#357
arpitjain099 wants to merge 1 commit into
containerd:mainfrom
arpitjain099:chore/pin-actions-sha

Conversation

@arpitjain099

Copy link
Copy Markdown

Two of the third-party actions in CI are referenced by floating refs, and marvinpinto/action-automatic-releases@latest is the riskiest kind: latest resolves to whatever the maintainer last tagged, with zero review on our side, and it runs in the release workflow where the token has write access. golangci-lint-action is pinned to the v9 major tag, which can also be moved.

Floating refs are the exact vector behind CVE-2025-30066 (tj-actions/changed-files), where an attacker rewrote existing tags to point at credential-stealing commits. Pinning to a verified commit SHA means the runner only ever executes the code we looked at.

This change pins:

  • golangci/golangci-lint-action (v9) in check.yml
  • docker/setup-buildx-action (v2) and both uses of marvinpinto/action-automatic-releases (latest) in release.yml

The tag name stays in a trailing comment for readability and future bumps. I deliberately left ci-build-image.yml alone because it is a reusable workflow (on: workflow_call), and skipped the GitHub-owned actions/* entries. Pins like these are what the OpenSSF Scorecard Pinned-Dependencies check looks for.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant