ci: pin remaining actions by SHA and declare read-only top-level token scope - #122
Merged
Merged
Conversation
Scorecard Pinned-Dependencies flagged tag-pinned uses across lint, static-analysis and terraform-test. Pins each to the SHA of the tag it already resolved to (checkout v4.4.0, setup-helm v4.3.1, upload-artifact v4.6.2, google-github-actions/auth v2.1.13, setup-gcloud v2.2.1, setup-terraform v3.1.2, setup-go v5.6.0), with the exact version in the trailing comment, matching the pins the other workflows already carry. Also normalizes existing pins whose comments carried only a bare major (or, in scorecard.yml, the wrong major) so zizmor's ref-version-mismatch has nothing to flag.
glenmessenger
force-pushed
the
chore/pin-remaining-actions
branch
from
September 30, 2026 21:57
8f8f689 to
460b464
Compare
Scorecard Token-Permissions scored 0: six workflows had no top-level permissions block, so the default GITHUB_TOKEN scope applied to any job without its own. Adds 'permissions: contents: read' at the top level of each; jobs that already declare broader job-level scopes (release, static-analysis, terraform-test) keep them unchanged, since job-level blocks override the top-level default.
zizmor ref-version-mismatch: the pinned SHA 3ea06614 is v3.38.1, while the floating v3 tag has since moved to 1190a975, so a bare '# v3' comment no longer describes the pin.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three commits, all in
.github/workflows. Originally split across #121 and #122, but the org-level zizmor scan audits only the workflow files a PR touches and enforces both rules together, so each half failed the scan on the finding the other half fixed. Combined here; #121 is closed in favor of this PR.1. Pin the remaining actions by SHA (Scorecard Pinned-Dependencies 6 → 10). Ten
uses:lines inlint.yaml,static-analysis.ymlandterraform-test.yamlwere tag-pinned. Each is pinned to the commit its tag currently resolves to, with the exact version in the trailing comment:11d5960a1a275c3bea165f8dc200f369e427ad8ab9cd54a340f1582bEvery SHA except the two google-github-actions ones is already pinned elsewhere in this repo. Existing pins whose comments carried only a bare major are normalized to the exact version;
scorecard.ymlhad# v5against the v4.4.0 checkout SHA and is corrected.2. Read-only top-level token scope (Scorecard Token-Permissions 0 → 10). Six workflows had no top-level
permissions:block, so jobs without their own inherited the repository default. Addspermissions: contents: readat the top level of each. Jobs that already declare broader job-level scopes (release.yamlcontents: write,static-analysis.ymlsecurity-events,terraform-test.yamlid-token) keep them unchanged, since job-level blocks override the top-level default.3. Exact version comment on the CodeQL upload-sarif pin. zizmor's ref-version-mismatch flagged it once
scorecard.ymlwas in the changed set: the pinned SHA3ea06614is v3.38.1, and the floatingv3tag has since moved on, so a bare# v3no longer describes the pin. Comment corrected; the SHA is unchanged.No behavior change in any workflow. Dependabot's
github-actionsecosystem keeps the pins current.