Skip to content

[LOW] Pin CI actions and restrict token permissions - #206

Open
OskarEichler wants to merge 1 commit into
enkessler:masterfrom
OskarEichler:codex/security-harden-workflow
Open

OskarEichler wants to merge 1 commit into
enkessler:masterfrom
OskarEichler:codex/security-harden-workflow

Conversation

@OskarEichler

Copy link
Copy Markdown

Summary

Pins both third-party CI actions to their current immutable commits and restricts the workflow token to read-only repository contents.

Security impact

LOW: this workflow executes repository tests on pushes and pull requests through action references that can move upstream. If a tag is retargeted or an action repository is compromised, changed third-party code can run with the workflow token's ambient permissions.

The patch does not upgrade either action:

  • actions/checkout@v2 → 0717577d45739eb3c851188b29f50ed6c0b2194e
  • ruby/setup-ruby@v1 → 95ef2b042f9d7a56d8268cba8559e2842e2ad01b

Verification

  • Both commits resolve through the GitHub API and contain action manifests.
  • The workflow parses as YAML.
  • Every active uses: entry is a full 40-character commit SHA.
  • Ruby 4.0.6 upstream suite: 70 examples, 0 failures.
  • git diff --check passes.

All Ruby-backed checks used rbenv.

Limitations

This preserves the existing action versions and matrix. It does not add automated action update tooling.

Breaking changes

None. Gem runtime and packaged file count are unchanged.

@eregon

eregon commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Seems not worth it, actually makes it harder to use newer versions.

@OskarEichler

Copy link
Copy Markdown
Author

Understood. This is a maintenance trade-off, not a demonstrated vulnerability in this test workflow, and there is no automated pin-update mechanism in the proposal. I will not push further pinning changes against the project preference.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants