Skip to content

Pin every GitHub Action to a commit SHA - #4

Merged
CodeStaple merged 1 commit into
mainfrom
security/pin-actions
Aug 30, 2026
Merged

CodeStaple merged 1 commit into
mainfrom
security/pin-actions

Conversation

@CodeStaple

Copy link
Copy Markdown
Contributor

Why this repo matters most

A tag is a moving pointer. actions/checkout@v4 is whatever the owner — or whoever takes the owner's account — last pointed v4 at.

That matters more here than anywhere else in the estate. release.yml runs with contents: write and GITHUB_TOKEN to publish the binaries people install. An action swapped underneath it does not just leak a build — it ships a backdoored CLI under our name to everyone who upgrades.

This is how trivy-action and kics-github-action were compromised.

The change

All 6 references pin a 40-character commit SHA, resolved from the tag already in use, with the version kept as a trailing comment:

-      - uses: actions/setup-go@v5
+      - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5

No version changes — behaviour-neutral. Renovate and Dependabot understand this form and keep proposing bumps.

ci.yml also gains a top-level permissions: contents: read; it had none. release.yml already declared its own, and the two publishing jobs keep their contents: write — a job-level block replaces the default rather than adding to it, so releases are unaffected.

Verification

Every uses: checked mechanically against [0-9a-f]{40}, and both files re-parsed as YAML after the edit. The diff is pins plus the one ci.yml permissions block — nothing else.

Note, separate from this PR

tael-cli is registered in Ankra as an application with a container image (registry.ankra.cloud/.../cli), but this repo has no build-and-publish.yml — it ships binaries via release.yml. So no image is ever built, and Ankra reports trivy_pending with 0 packages and 0 code findings.

Those zeros read as "clean" on the dashboard when they actually mean "never scanned". Worth either deregistering the application or giving this repo its own scan step.

Related

Same fix merged in taelio/frontend#4, taelio/backend#2, taelio/agent#2.

A tag is a moving pointer: `actions/checkout@v4` is whatever the owner, or
whoever takes the owner's account, last pointed v4 at.

That matters more here than anywhere else in the estate. release.yml runs with
`contents: write` and GITHUB_TOKEN to publish the binaries people install, so
an action swapped underneath it does not just leak a build — it ships a
backdoored CLI under our name to everyone who upgrades.

All 6 references now pin the SHA the tag currently resolves to, with the
version kept as a trailing comment so the file still reads and Renovate and
Dependabot keep proposing bumps. No versions change.

ci.yml also gains a top-level `permissions: contents: read`; it had none.
release.yml already declared its own, and the two jobs that publish keep their
`contents: write` — a job-level block replaces the default rather than adding
to it.
@CodeStaple
CodeStaple merged commit 9025537 into main Aug 30, 2026
1 check passed
@CodeStaple
CodeStaple deleted the security/pin-actions branch August 30, 2026 10:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant