Skip to content

ci: pin remaining actions by SHA and declare read-only top-level token scope - #122

Merged
glenmessenger merged 3 commits into
mainfrom
chore/pin-remaining-actions
Sep 30, 2026
Merged

glenmessenger merged 3 commits into
mainfrom
chore/pin-remaining-actions

Conversation

@glenmessenger

@glenmessenger glenmessenger commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Three commits, all in .github/workflows. Originally split across #121 and #122, but the org-level zizmor scan audits only the workflow files a PR touches and enforces both rules together, so each half failed the scan on the finding the other half fixed. Combined here; #121 is closed in favor of this PR.

1. Pin the remaining actions by SHA (Scorecard Pinned-Dependencies 6 → 10). Ten uses: lines in lint.yaml, static-analysis.yml and terraform-test.yaml were tag-pinned. Each is pinned to the commit its tag currently resolves to, with the exact version in the trailing comment:

Action SHA Version
actions/checkout 11d5960a v4.4.0
azure/setup-helm 1a275c3b v4.3.1
actions/upload-artifact ea165f8d v4.6.2
google-github-actions/auth c200f369 v2.1.13
google-github-actions/setup-gcloud e427ad8a v2.2.1
hashicorp/setup-terraform b9cd54a3 v3.1.2
actions/setup-go 40f1582b v5.6.0

Every SHA except the two google-github-actions ones is already pinned elsewhere in this repo. Existing pins whose comments carried only a bare major are normalized to the exact version; scorecard.yml had # v5 against the v4.4.0 checkout SHA and is corrected.

2. Read-only top-level token scope (Scorecard Token-Permissions 0 → 10). Six workflows had no top-level permissions: block, so jobs without their own inherited the repository default. Adds permissions: contents: read at the top level of each. Jobs that already declare broader job-level scopes (release.yaml contents: write, static-analysis.yml security-events, terraform-test.yaml id-token) keep them unchanged, since job-level blocks override the top-level default.

3. Exact version comment on the CodeQL upload-sarif pin. zizmor's ref-version-mismatch flagged it once scorecard.yml was in the changed set: the pinned SHA 3ea06614 is v3.38.1, and the floating v3 tag has since moved on, so a bare # v3 no longer describes the pin. Comment corrected; the SHA is unchanged.

No behavior change in any workflow. Dependabot's github-actions ecosystem keeps the pins current.

@glenmessenger glenmessenger added the security Security-relevant defect or hardening label Sep 30, 2026
Scorecard Pinned-Dependencies flagged tag-pinned uses across lint,
static-analysis and terraform-test. Pins each to the SHA of the tag it
already resolved to (checkout v4.4.0, setup-helm v4.3.1,
upload-artifact v4.6.2, google-github-actions/auth v2.1.13,
setup-gcloud v2.2.1, setup-terraform v3.1.2, setup-go v5.6.0), with
the exact version in the trailing comment, matching the pins the other
workflows already carry. Also normalizes existing pins whose comments
carried only a bare major (or, in scorecard.yml, the wrong major) so
zizmor's ref-version-mismatch has nothing to flag.
@glenmessenger
glenmessenger force-pushed the chore/pin-remaining-actions branch from 8f8f689 to 460b464 Compare September 30, 2026 21:57
Scorecard Token-Permissions scored 0: six workflows had no top-level
permissions block, so the default GITHUB_TOKEN scope applied to any job
without its own. Adds 'permissions: contents: read' at the top level of
each; jobs that already declare broader job-level scopes (release,
static-analysis, terraform-test) keep them unchanged, since job-level
blocks override the top-level default.
zizmor ref-version-mismatch: the pinned SHA 3ea06614 is v3.38.1, while
the floating v3 tag has since moved to 1190a975, so a bare '# v3'
comment no longer describes the pin.
@glenmessenger glenmessenger changed the title ci: pin the remaining GitHub Actions by commit SHA Sep 30, 2026
@glenmessenger
glenmessenger merged commit bec9149 into main Sep 30, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security-relevant defect or hardening

1 participant