From 45731b3802e018412a76ba38ae0fa1200b3f4b7e Mon Sep 17 00:00:00 2001 From: phil Date: Tue, 6 Oct 2026 10:19:53 +0900 Subject: [PATCH] Pin workflow actions and scope token permissions Scorecard flagged two tag-pinned actions/checkout uses in release.yml and top-level contents/packages write in helm-publish.yml. - Pin the sync-community-operators checkouts by commit SHA. - helm-publish.yml: top-level contents: read; write scopes move to the publish job. - Makefile audit: pin govulncheck and gosec instead of @latest so the security gate is reproducible. Co-Authored-By: Claude Fable 5.1 Signed-off-by: phil --- .github/workflows/helm-publish.yml | 8 +++++--- .github/workflows/release.yml | 4 ++-- Makefile | 6 ++++-- 3 files changed, 11 insertions(+), 7 deletions(-) diff --git a/.github/workflows/helm-publish.yml b/.github/workflows/helm-publish.yml index 7cd4e33b..9648f129 100644 --- a/.github/workflows/helm-publish.yml +++ b/.github/workflows/helm-publish.yml @@ -28,9 +28,7 @@ on: required: true permissions: - contents: write # push to gh-pages + create per-chart Release - packages: write # push helm chart to ghcr.io OCI registry - pages: read + contents: read # least-privilege at top level; write scoped per job concurrency: group: helm-publish-${{ github.repository }} @@ -39,6 +37,10 @@ concurrency: jobs: publish: runs-on: ubuntu-latest + permissions: + contents: write # push to gh-pages + create per-chart Release + packages: write # push helm chart to ghcr.io OCI registry + pages: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4bba0eac..43d4886d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -266,13 +266,13 @@ jobs: contents: read steps: - name: Checkout release repo - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 with: repository: keiailab/postgres-operator ref: ${{ needs.preflight.outputs.tag }} path: source - name: Checkout community-operators fork - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 with: repository: eightynine01/community-operators token: ${{ secrets.COMMUNITY_OPERATORS_PAT }} diff --git a/Makefile b/Makefile index dfc03c82..d41dea6e 100644 --- a/Makefile +++ b/Makefile @@ -217,13 +217,13 @@ hooks-check: ## 현재 repo 에 lefthook hook 이 설치되어 있는지 확인 .PHONY: audit audit: ## govulncheck + trivy + gosec — RFC 0002 L3 security 게이트 (3-repo 정합). @echo "=== govulncheck (call-graph CVE) ===" - @command -v $(GOBIN)/govulncheck >/dev/null 2>&1 || go install golang.org/x/vuln/cmd/govulncheck@latest + @command -v $(GOBIN)/govulncheck >/dev/null 2>&1 || go install golang.org/x/vuln/cmd/govulncheck@$(GOVULNCHECK_VERSION) $(GOBIN)/govulncheck ./... @echo "=== trivy fs (lockfile + base CVE) ===" @command -v trivy >/dev/null 2>&1 || { echo "[error] trivy not installed: brew install trivy (or apt install trivy)"; exit 1; } trivy fs --severity HIGH,CRITICAL --exit-code 1 --ignore-unfixed --skip-dirs vendor,bin,tmp . @echo "=== gosec (HIGH only) ===" - @command -v $(GOBIN)/gosec >/dev/null 2>&1 || go install github.com/securego/gosec/v2/cmd/gosec@latest + @command -v $(GOBIN)/gosec >/dev/null 2>&1 || go install github.com/securego/gosec/v2/cmd/gosec@$(GOSEC_VERSION) $(GOBIN)/gosec -quiet -severity high ./internal/... .PHONY: test-scripts @@ -610,6 +610,8 @@ ENVTEST_K8S_VERSION ?= $(shell v='$(call gomodver,k8s.io/api)'; \ printf '%s\n' "$$v" | sed -E 's/^v?[0-9]+\.([0-9]+).*/1.\1/') GOLANGCI_LINT_VERSION ?= v2.8.0 +GOVULNCHECK_VERSION ?= v1.8.0 +GOSEC_VERSION ?= v2.29.0 .PHONY: kustomize kustomize: $(KUSTOMIZE) ## Download kustomize locally if necessary. $(KUSTOMIZE): $(LOCALBIN)