Skip to content

ci: pin actions by SHA and scope write tokens - #412

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
ci/harden-workflows
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
ci/harden-workflows

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

What / why

Closes Scorecard PinnedDependencies (43) and TokenPermissions (5).

  • Every uses: pinned to a commit SHA, tag kept as # vN comment (SHAs resolved via gh api repos/<a>/commits/<tag>). deploy/catalog/Dockerfile opm base pinned by index digest sha256:8872de9b… (no trailing comment on the FROM line).
  • security-scan.yml: govulncheck pinned to v1.8.0 (latest tag) instead of @latest.
  • Top-level permissions: contents: read in helm-publish.yml, release.yml, security-scan.yml; write scopes moved into the jobs that use them:
    • helm-publish publish: contents/packages write, pages read (unchanged set)
    • release image: packages + id-token write; sbom: packages read; github-release: contents write
    • security-scan trivy-fs/trivy-image: security-events write (SARIF upload)
  • scripts/resume-after-unflag.sh: curl … | python3 (downloadThenRun) replaced by gh api rate_limit --jq .resources.core.limit — same value, no download-then-execute.

Verification

  • grep -rn 'uses:' .github/workflows | grep -v '@[0-9a-f]\{40\}' | grep -v 'docker://' | grep -v 'uses: \./' → empty
  • actionlint v1.7.7 on changed workflows → clean (only pre-existing shellcheck style notes in untouched go-licenses.yml)
  • docker buildx build --check deploy/catalog and . → no warnings
  • release/helm-publish permission split is exercised by the v1.16.10 release run.

🤖 Generated with Claude Code

Scorecard reports 43 PinnedDependencies and 5 TokenPermissions alerts.

- Pin every `uses:` to a commit SHA (tag kept as comment) and the
  catalog opm base image by digest.
- Pin govulncheck to v1.8.0 instead of @latest.
- helm-publish, release, security-scan: top-level `contents: read`;
  write scopes move to the jobs that use them (publish; image,
  sbom read, github-release; trivy-fs/trivy-image SARIF upload).
- resume-after-unflag.sh: read the rate limit with `gh api` instead
  of piping curl into python (downloadThenRun).

Behavior is unchanged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@KeiaiLab-PHIL
KeiaiLab-PHIL enabled auto-merge (squash) October 6, 2026 01:35
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit 9b799ed into main Oct 6, 2026
15 of 16 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the ci/harden-workflows branch October 6, 2026 01:44
KeiaiLab-PHIL added a commit that referenced this pull request Oct 6, 2026
Security release, also a code release: tag, chart version and
appVersion are aligned so release.yml builds and publishes the image.

Includes: Go toolchain 1.26.8 and vulnerable module bumps (#411),
workflow hardening (#412), Dependabot (#413), MongoDB 9.0 support with
9.0.2 and exporter 0.53.0 as defaults (#414), fuzz test (#422).

Bundle regenerated with `make bundle VERSION=1.16.10` (ADR-0038
parity). artifacthub.io/images moves the operator to v1.16.10 and
keeps the upstream mongo/exporter images whitelisted;
containsSecurityUpdates is true.

Signed-off-by: phil <phil@keiailab.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant